CVE-2026-79988

Summary

The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.

Affected Software

VendorProductVersion RangeStatus
craftcmscms4.0.0-RC1 < 4.18.3affected
craftcmscms5.0.0-RC1 < 5.10.7affected

Weaknesses

  • CWE-693: CWE-693 Protection Mechanism Failure

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References