Report: CVE-2026-32263 - Craft CMS vulnerable to behavior injection RCE via EntryTypesController

Report: CVE-2026-32263 - Craft CMS vulnerable to behavior injection RCE via EntryTypesController

CVE ID :CVE-2026-32263 Published : March 16, 2026, 6:57 p.m. | 1 hour, 11 minutes ago Description :Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTypesController.php, the $settings array from parse_str is passed directly to Craft::configure() without Component::cleanseConfig(). This allows injecting Yii2 behavior/event handlers via

CVE Details

Published
March 16, 2026
Affected Product: php