CVE-2026-56382 — craftcms/cms
CVE-2026-56382 is a Code Injection vulnerability in craftcms/cms. A fix is available for craftcms/cms — see the affected versions and patch details below.
Craft CMS - Remote Code Execution via Missing Config Sanitization in FieldsController
Exploitation Status
Proof-of-concept exploit code exists
- CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
- A successful exploit gives an attacker total control of the affected component, not partial access.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-56382.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Real-World Exposure
craftcms/cmsReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.
Description
The actionRenderCardPreview() method in FieldsController passes the fieldLayoutConfig POST parameter directly to Fields::createLayout() without calling Component::cleanseConfig(). This allows Yii2 event handler injection via on eventName keys in the config array, leading to arbitrary code execution.
This is the same vulnerability pattern that was fixed in GHSA-4484-8v2f-5748 (same file, _fldComponent method correctly uses cleanseConfig), GHSA-qx2q-q59v-wf3j (EntryTypesController), and GHSA-2fph-6v5w-89hh (ElementIndexesController).
PoC
As an admin user with a valid session:
POST /admin/actions/fields/render-card-preview HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Cookie: CraftSessionId=<session>
fieldLayoutConfig[on+init]=phpinfo&CRAFT_CSRF_TOKEN=<token>
When the FieldLayout object is constructed, Yii2 processes the on init key as an event handler registration. During Component::init(), the init event is triggered, calling phpinfo(). The phpinfo output (which includes environment variables, potentially containing database credentials and CRAFT_SECURITY_KEY) will appear in the response.
Impact
An authenticated admin can achieve RCE through Yii2 event handler injection. While this requires admin access (same as GHSA-4484-8v2f-5748, which was rated moderate), it allows arbitrary PHP function execution and information disclosure via phpinfo.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐘Packagist | craftcms/cms | ≥ 5.5.0&&< 5.9.14 | 5.9.14composer require craftcms/cms:^5.9.14 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for craftcms/cms, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update craftcms/cms to 5.9.14 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-56382 is resolved across your whole dependency graph.
Workarounds
Stop passing untrusted input into the interpreter or shell: call the affected binary with an argument array rather than a composed command string, reject anything outside a strict allowlist of expected values, and run the component under an account that cannot reach beyond the work it legitimately does.
Frequently Asked Questions
Is CVE-2026-56382 in your dependencies?
Find it across Packagist, including transitive dependencies.