{"id":"CVE-2026-32264","aliases":["GHSA-4484-8v2f-5748"],"url":"https://o3.security/vulnerability/CVE-2026-32264","summary":"Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController","details":"The fix for https://github.com/advisories/GHSA-7jx7-3846-m7w7 (commit https://github.com/craftcms/cms/commit/395c64f0b80b507be1c862a2ec942eaacb353748) only patched `src/services/Fields.php`, but the same vulnerable pattern exists in `ElementIndexesController` and `FieldsController`.\n\nYou need Craft control panel administrator permissions, and allowAdminChanges must be enabled for this to work.\n\nAn attacker can use the same gadget chain from the original advisory to achieve RCE.\n\nUsers should update to Craft 4.17.5 and 5.9.11 to mitigate the issue.","published":"2026-03-16T19:02:22.720Z","modified":"2026-08-12T03:51:17.273431440Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"4.17.5"},{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"5.9.11"}],"fix":{"url":"https://github.com/craftcms/cms/commit/78d181e12e0b15e1300f54ec85f19859d3300f70","label":"craftcms/cms@78d181e"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32264.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-4484-8v2f-5748"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-7jx7-3846-m7w7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32264"},{"type":"FIX","url":"https://github.com/craftcms/cms/commit/78d181e12e0b15e1300f54ec85f19859d3300f70"},{"type":"FIX","url":"https://github.com/craftcms/cms/commit/dfec46362fcb40b330ce8a4d8136446e65085620"},{"type":"PACKAGE","url":"https://github.com/craftcms/cms"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:17.273431440Z"}}