CVE-2026-86732 | Craft CMS up to 5.10.11 Element Index Endpoint normalizeTransform criteria input validation

SecurityVulns

A vulnerability categorized as critical has been discovered in Craft CMS CMS up to 5.10.11. The impacted element is the function ImageTransforms::normalizeTransform of the component Element Index Endpoint. Such manipulation of the argument criteria leads to improper input validation.

This vulnerability is referenced as CVE-2026-86732. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More