CVE-2026-105985 - Authenticated RCE via render-components Entry Type overrides
CVE ID :CVE-2026-105985 Published : Oct. 6, 2026, 10:23 a.m. | 1 hour, 5 minutes ago Description :Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can...