CVE-2026-56382 | Craft CMS up to 5.9.13 POST Parameter actionRenderCardPreview fieldLayoutConfig code injection (GHSA-86vw-x4ww-x467 / EUVD-2026-38176)
A vulnerability has been found in Craft CMS up to 5.9.13 and classified as critical. Affected is the function FieldsController::actionRenderCardPreview of the component POST Parameter Handler. This manipulation of the argument fieldLayoutConfig causes code injection.
This vulnerability appears as CVE-2026-56382. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.