CVE-2026-72778 | Craft CMS up to 4.18.1/5.10.5 Condition createCondition condition.config os command injection

SecurityVulns

A vulnerability was found in Craft CMS up to 4.18.1/5.10.5. It has been rated as problematic. Impacted is the function Conditions::createCondition of the component Condition. This manipulation of the argument condition.config causes os command injection.

The identification of this vulnerability is CVE-2026-72778. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More