← Back

CVE-2026-79988

nvd nist
Published: Aug 27, 2026Modified: Aug 28, 2026Deferred

JSON object

Loading...
8.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: 7004884b-51e2-48e8-b4a2-5ca29e80453e (Secondary)

Description

The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.

References (3)

Source: 7004884b-51e2-48e8-b4a2-5ca29e80453e
Source: 7004884b-51e2-48e8-b4a2-5ca29e80453e
Source: 7004884b-51e2-48e8-b4a2-5ca29e80453e

Timeline

No history available yet.