Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-92592: Craft CMS lets attackers run commands through a cookie

CVE-2026-92592 · published 12 days ago
Summary

Versions of Craft CMS from 4.8.0 up to 4.18.5 and from 5.0.0 up to 5.10.12 accept a specially crafted signed cookie and then execute code on the server. An attacker who can log in with a regular user account can use this to run any command the web server can run. Update Craft CMS to version 4.18.6 or later (or 5.10.13 or later) to stop the problem.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
craftcms cms < 4.18.6
< 5.10.13
Original advisory text
Craft CMS before 4.18.6 Remote Code Execution via signed cookie
Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound to its purpose (Yii's cookieValidationKey is derived from the same Craft securityKey used for signed request parameters). An authenticated, non-administrator user (Control Panel access is not required) can set the cookie via the license-shun endpoint and transplant the signed envelope into the redirect parameter; on a successful login, Craft validates the signature and renders the authenticated bytes as an unsandboxed Twig template, where Twig's map filter accepts a string callback and allows PHP system() to execute arbitrary operating-system commands as the web-server user. Exploitation requires an account using password authentication without active 2FA, the default request configuration, and availability of PHP system(). The issue is fixed in 4.18.6 and 5.10.13.
Severity
8.7 High
CVSS 3.1: 8.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
Timeline
Published16 Sep 2026
Updated29 Sep 2026
First seen16 Sep 2026
Sources
CVE-2026-92592 · MITRE
Track software like this
Free during beta