๐Ÿ” CVE Alert

CVE-2026-79988

UNKNOWN 0.0

Authenticated RCE through Twig sandbox escape

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.

CWE CWE-693
Vendor craftcms
Product cms
Published Aug 27, 2026
Last Updated Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for craftcms cms

Be the first to know when new unknown vulnerabilities affecting craftcms cms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

craftcms / cms
4.0.0-RC1 < 4.18.3 5.0.0-RC1 < 5.10.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hckrt.com: https://www.hckrt.com/hacktivity/HCKRT-8RQQ7K github.com: https://github.com/craftcms/cms/releases/tag/5.10.7 github.com: https://github.com/craftcms/cms

Credits

๐Ÿ” Oskar Zeino-Mahmalat (@oskar-cure53) Hackrate