Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32264

25
FAUCET Score

CVE-2026-32264 is a high-severity remote code execution (RCE) vulnerability impacting Craft CMS versions 4.0.0-RC1 through 4.17.4 and 5.0.0-RC1 through 5.9.10. This behavior injection flaw, found in ElementIndexesController and FieldsController, requires an attacker to possess administrator permissions and have the 'allowAdminChanges' setting enabled. With a CVSS score of 7.2 (High), successful exploitation could lead to complete compromise of confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on CISA's Known Exploited Vulnerabilities catalog.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.0.0.1, < 4.17.5CPE matchmatch criteria
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
>= 5.0.1, < 5.9.11CPE matchmatch criteria
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
4.0.0CPE matchmatch criteria
cpe:2.3:a:craftcms:craft_cms:4.0.0:-:*:*:*:*:*:*
4.0.0CPE matchmatch criteria
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc1:*:*:*:*:*:*
4.0.0CPE matchmatch criteria
cpe:2.3:a:craftcms:craft_cms:4.0.0:rc2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.6HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.52%
Probability of exploitation in next 30 days
EPSS Percentile
40.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0052 is in the 18th percentile among its peer group of 5,538 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: craftcms/cmsFixed in: 4.17.5
composerpatch availablevia ghsa
Product: craftcms/cmsFixed in: 5.9.11

Vendor Advisories (1)

composerGHSA-4484-8v2f-5748high

Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController

Mar 16, 2026

References

github.com / craftcms/cms/commit/78d181e12e0b15e1300f54ec85f19859d3300f70
Patch
github.com / craftcms/cms/commit/dfec46362fcb40b330ce8a4d8136446e65085620
Patch
github.com / craftcms/cms/security/advisories/GHSA-4484-8v2f-5748
PatchVendor Advisory
github.com / craftcms/cms/security/advisories/GHSA-7jx7-3846-m7w7
Vendor Advisory