{"id":"GHSA-qx2q-q59v-wf3j","summary":"Craft CMS vulnerable to behavior injection RCE via EntryTypesController","details":"The fix for GHSA-7jx7-3846-m7w7 (commit 395c64f0b80b507be1c862a2ec942eaacb353748) only patched `src/services/Fields.php`, but the same vulnerable pattern exists in `EntryTypesController::actionApplyOverrideSettings()`.\n\nIn `src/controllers/EntryTypesController.php` lines 381-387:\n\n```php\n$settingsStr = $this-\u003erequest-\u003egetBodyParam('settings');\nparse_str($settingsStr, $postedSettings);\n$settingsNamespace = $this-\u003erequest-\u003egetRequiredBodyParam('settingsNamespace');\n$settings = array_filter(ArrayHelper::getValue($postedSettings, $settingsNamespace, []));\n\nif (!empty($settings)) {\n    Craft::configure($entryType, $settings);\n```\n\nThe `$settings` array from `parse_str` is passed directly to `Craft::configure()` without `Component::cleanseConfig()`. This allows injecting Yii2 behavior/event handlers via `as ` or `on ` prefixed keys, the same attack vector as the original advisory.\n\nYou need Craft control panel administrator permissions, and `allowAdminChanges` must be enabled for this to work.\n\nAn attacker can use the same gadget chain from the original advisory to achieve RCE.\n\nUsers should update to Craft 5.9.11 to mitigate the issue.","aliases":["CVE-2026-32263"],"modified":"2026-04-02T13:29:24.761454600Z","published":"2026-03-16T18:12:32Z","related":["CVE-2026-32263"],"database_specific":{"github_reviewed_at":"2026-03-16T18:12:32Z","nvd_published_at":"2026-03-16T20:16:19Z","cwe_ids":["CWE-470"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/craftcms/cms/security/advisories/GHSA-7jx7-3846-m7w7"},{"type":"WEB","url":"https://github.com/craftcms/cms/security/advisories/GHSA-qx2q-q59v-wf3j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32263"},{"type":"WEB","url":"https://github.com/craftcms/cms/commit/d37389dbffafa565143be40a2ab1e1db22a863f7"},{"type":"PACKAGE","url":"https://github.com/craftcms/cms"}],"affected":[{"package":{"name":"craftcms/cms","ecosystem":"Packagist","purl":"pkg:composer/craftcms/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.6.0"},{"fixed":"5.9.11"}]}],"versions":["5.6.0","5.6.0.1","5.6.0.2","5.6.1","5.6.10","5.6.10.1","5.6.10.2","5.6.11","5.6.12","5.6.13","5.6.14","5.6.15","5.6.16","5.6.17","5.6.2","5.6.3","5.6.4","5.6.5","5.6.5.1","5.6.6","5.6.7","5.6.8","5.6.9","5.6.9.1","5.7.0","5.7.0-beta.1","5.7.0-beta.2","5.7.1","5.7.1.1","5.7.10","5.7.11","5.7.2","5.7.3","5.7.4","5.7.5","5.7.6","5.7.7","5.7.8","5.7.8.1","5.7.8.2","5.7.9","5.8.0","5.8.1","5.8.10","5.8.11","5.8.12","5.8.13","5.8.13.1","5.8.13.2","5.8.14","5.8.15","5.8.16","5.8.17","5.8.18","5.8.19","5.8.2","5.8.20","5.8.21","5.8.22","5.8.23","5.8.3","5.8.4","5.8.5","5.8.6","5.8.7","5.8.8","5.8.9","5.9.0","5.9.0-beta.1","5.9.0-beta.2","5.9.1","5.9.10","5.9.2","5.9.3","5.9.4","5.9.5","5.9.6","5.9.7","5.9.8","5.9.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-qx2q-q59v-wf3j/GHSA-qx2q-q59v-wf3j.json","last_known_affected_version_range":"\u003c= 5.9.10"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}