Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-79987: Craft CMS lets low‑privilege users run system commands

CVE-2026-79987 · published 19 days ago
Summary

A user who can only access the Craft CMS control panel (with the basic accessCp right) can cause the web server to run operating‑system commands. This could let an attacker manipulate files or data on the server. Apply the latest Craft CMS update and restrict control‑panel permissions to only trusted administrators.

What to do
  • Update craftcms cms to version 5.10.13 or later.
Affected software
VendorProductAffected versions
craftcms cms < 5.10.13
Original advisory text
Low-privilege RCE through element-search eager loading
A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.
Severity
8.7 High
CVSS 3.1: 8.8 (NVD)
CVSS 4.0: 8.7 (NVD)
Exploitation
EPSS <1%
Type
CWE-470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Timeline
Published10 Sep 2026
Updated27 Sep 2026
First seen10 Sep 2026
Sources
CVE-2026-79987 · MITRE
Track software like this
Free during beta