CVE-2026-79988
Authenticated RCE through Twig sandbox escape
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.
| CWE | CWE-693 |
| Vendor | craftcms |
| Product | cms |
| Published | Aug 27, 2026 |
| Last Updated | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for craftcms cms
Be the first to know when new unknown vulnerabilities affecting craftcms cms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
craftcms / cms
4.0.0-RC1 < 4.18.3 5.0.0-RC1 < 5.10.7
References
Credits
๐ Oskar Zeino-Mahmalat (@oskar-cure53) Hackrate