
CraftCMS has an RCE vulnerability via relational conditionals in the control panel
CVE-2026-31857 is a remote code execution issue in Craft CMS relational condition rules. BaseElementSelectConditionRule::getElementIds() renders user-controlled input as an unsandboxed Twig template. An authenticated Control Panel user can submit a crafted condition through an element listing endpoint and execute commands on the server. Administrator privileges are not required.
Craft CMS 4.0.0-beta.1 through 4.17.3 and 5.0.0-RC1 through 5.9.8 are affected. This PoC uses the Craft 5 element-index request shape.
Python 3 with only the standard library is required. Supply the base URL and a Control Panel username; the script prompts for the password:
python3 poc.py https://craft.example editor
Enter commands at cmd>, or enter exit to quit. The current working directory persists between commands. To launch a long-running command, end it with &; its input and output are detached from the HTTP request and its output is discarded. Command output returned through the response header is limited to the last 1200 bytes.