CVE-2026-44011 is an authenticated remote code execution vulnerability in Craft CMS affecting versions 4.0.0 through 4.17.11 and 5.x through 5.9.17. Request-controlled condition field-layout data is hydrated into a Yii FieldLayout object without a Component::cleanseConfig() boundary. Because Craft CMS configures models before invoking the parent constructor, attacker-controlled special configuration keys can take effect during object construction. FieldLayout initialization subsequently triggers an event in the same request, allowing malicious Yii configuration to execute arbitrary operating-system commands.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains README.md (1,530 bytes) and a standalone exploit.py (4,612 bytes). The README documents affected Craft CMS version ranges, prerequisites, usage, an example callback, and advisory GHSA-qrgm-p9w5-rrfw; no CVE identifier is supplied. The Python script uses requests for session management and json for payload serialization. It retrieves a CSRF token, authenticates, then submits a malicious condition configuration to the element-search action. The configuration attaches a Yii AttributeTypecastBehavior and routes a typecasting callback through Psy's ConsoleProcessus.execute to run a Bash command. The basic payload defaults to id and attempts HTTP-based output exfiltration rather than opening a reverse shell. This is exploit code, not merely a detector, with no evident fake-exploit behavior in the supplied files. Reliability limitations include inconsistent post-login CSRF parsing, treating HTTP 200/302 as sufficient evidence of login, broad exception handling, and interpreting a response code of zero as success without independently confirming execution. No version detection is implemented. Analysis is static; exploitability was not verified. The original repository URL, git reference, and archive size were not provided; empty strings and zero represent unavailable repository metadata, not measured values.
The repository contains a README and a single Python 3 exploit program, exploit.py. It is a standalone authenticated RCE exploit rather than a framework module. The script logs in with supplied Craft CMS credentials, obtains/parses a CSRF token, optionally detects and validates the Craft version, and submits a malicious element-search condition to the configurable control-panel endpoint. The condition abuses missing Yii configuration cleansing to attach a behavior that invokes a command-execution callable during object construction/save processing. For output collection, the exploit starts a threaded HTTP listener on all local interfaces, makes the target download a tokenized shell script, then triggers the script. The script executes the operator-selected command, captures combined output, POSTs it back to a second tokenized listener path, and deletes temporary artifacts. The supplied README identifies affected Craft CMS ranges, notes that low-privilege authenticated users are sufficient, and documents callback, TLS-verification, timeout, site-ID, element-type, and control-panel-path options.
This three-file repository contains an MIT license, brief usage documentation, and a single Python executable, `exploit.py`. The script is an authenticated RCE exploit for the claimed CVE-2026-44011 in Craft CMS. It logs in with supplied credentials, extracts Craft's CSRF token, parses the application footer to identify Craft CMS versions, and considers Craft CMS 4.0.0–4.17.11 and 5.0.0–5.9.17 vulnerable. It targets an uncleansed ElementSearchController `condition` parameter and constructs a Yii2 AttributeTypecastBehavior gadget chain intended to invoke an attacker-controlled callable. For reliable command execution and output collection, it starts a local threaded HTTP server with randomized stage/result paths, makes the target fetch a temporary shell script, executes that script, and receives captured output by HTTP POST. An optional mode creates a base64-wrapped Bash reverse shell. No third-party exploit framework is used.
The repository contains a README and one standalone Python 3 exploit, `cve-2026-44011.py`. It is a functional authenticated RCE proof of concept for CVE-2026-44011 affecting Craft CMS 4.0.0 through 4.17.11 and 5.0.0 through 5.9.17. The script logs in using supplied Craft credentials, obtains and uses a CSRF token, and submits a crafted field-layout/condition payload built around Yii deserialization behavior and the `Psy\Readline\Hoa\ConsoleProcessus` command gadget. It shells out to curl for HTTP requests while maintaining a cookie jar. A built-in threaded HTTP server stages check and shell scripts, receives `id` output or script-verification callbacks, and a TCP listener accepts the resulting reverse shell. The code includes input/result validation, timeouts, and best-effort deletion of staged remote files. It is not tied to Metasploit, Nuclei, or another exploit framework.
This is a standalone Python proof-of-concept exploit for CVE-2026-44011 in Craft CMS, not a Metasploit, Nuclei, or other exploit-framework module. The repository contains the primary executable cve-2026-44011.py, a requests-only dependency file, README documentation, and Python unittest coverage in tests/test_cve_2026_44011.py. The script authenticates to the configurable Craft control-panel path using CSRF handling, parses the displayed Craft version, verifies it falls in the documented affected 4.x or 5.x ranges unless --force is used, and performs a benign authenticated element-search request before exploitation. It then POSTs a malicious nested condition/field-layout configuration to the element-search action. The configuration abuses Yii behavior and event wiring to invoke PsySH's ConsoleProcessus::execute callable, enabling shell command execution. For reliable output capture, it launches a threaded HTTP listener, causes the target to curl a one-time staged shell script, and separately triggers that script; the script executes the supplied command and uploads output to the listener. Tests validate payload structure, CSRF/login behavior, version handling, listener staging/result collection, and failure paths.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.