CVE-2026-79987
largeAuthenticated OS Command Execution in Craft CMS Control Panel
Craft CMS contains a vulnerability (CWE-470, unsafe reflection) that allows a remote, authenticated, non-admin Control Panel user holding only the accessCp permission to execute operating system commands. Triggering the flaw requires nothing more than network access to the Control Panel and a low-privilege login, with no user interaction needed. Successful exploitation yields command execution as the PHP web worker on the web server, with high impact on the confidentiality, integrity, and availability of the local application, and potentially a foothold for lateral movement depending on the worker's privileges. All Craft CMS deployments that grant Control Panel access to non-administrator accounts are affected, while sites whose CP users are all admins are not exposed via this path. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists at this time.
What to do: Upgrade Craft CMS to the latest patched release per the vendor advisory, as the source data does not specify fixed version numbers. In the meantime, audit Control Panel accounts and remove or restrict non-admin users who hold only the accessCp permission, and monitor for unexpected child processes spawned by the PHP web worker.
| Craft CMS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.
- Weakness
- CWE-470
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.