{"id":"CVE-2026-56382","aliases":["GHSA-86vw-x4ww-x467"],"url":"https://o3.security/vulnerability/CVE-2026-56382","summary":"Craft CMS - Remote Code Execution via Missing Config Sanitization in FieldsController","details":"The `actionRenderCardPreview()` method in `FieldsController` passes the `fieldLayoutConfig` POST parameter directly to `Fields::createLayout()` without calling `Component::cleanseConfig()`. This allows Yii2 event handler injection via `on eventName` keys in the config array, leading to arbitrary code execution.\n\nThis is the same vulnerability pattern that was fixed in GHSA-4484-8v2f-5748 (same file, `_fldComponent` method correctly uses `cleanseConfig`), GHSA-qx2q-q59v-wf3j (EntryTypesController), and GHSA-2fph-6v5w-89hh (ElementIndexesController).\n\n## PoC\n\nAs an admin user with a valid session:\n\n```\nPOST /admin/actions/fields/render-card-preview HTTP/1.1\nContent-Type: application/x-www-form-urlencoded\nCookie: CraftSessionId=<session>\n\nfieldLayoutConfig[on+init]=phpinfo&CRAFT_CSRF_TOKEN=<token>\n```\n\nWhen the FieldLayout object is constructed, Yii2 processes the `on init` key as an event handler registration. During `Component::init()`, the `init` event is triggered, calling `phpinfo()`. The phpinfo output (which includes environment variables, potentially containing database credentials and `CRAFT_SECURITY_KEY`) will appear in the response.\n\n## Impact\n\nAn authenticated admin can achieve RCE through Yii2 event handler injection. While this requires admin access (same as GHSA-4484-8v2f-5748, which was rated moderate), it allows arbitrary PHP function execution and information disclosure via phpinfo.","published":"2026-06-21T13:26:58.994Z","modified":"2026-08-12T03:51:16.879146954Z","cvss":null,"epss":{"score":0.00886,"percentile":0.57481,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"5.9.14"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56382.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-86vw-x4ww-x467"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56382"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/craft-cms-remote-code-execution-via-missing-config-sanitization-in-fieldscontroller"},{"type":"PACKAGE","url":"https://github.com/craftcms/cms"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:16.879146954Z"}}