ZeroHour

CVE-2026-79987

large

Authenticated OS Command Execution in Craft CMS Control Panel

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

Craft CMS contains a vulnerability (CWE-470, unsafe reflection) that allows a remote, authenticated, non-admin Control Panel user holding only the accessCp permission to execute operating system commands. Triggering the flaw requires nothing more than network access to the Control Panel and a low-privilege login, with no user interaction needed. Successful exploitation yields command execution as the PHP web worker on the web server, with high impact on the confidentiality, integrity, and availability of the local application, and potentially a foothold for lateral movement depending on the worker's privileges. All Craft CMS deployments that grant Control Panel access to non-administrator accounts are affected, while sites whose CP users are all admins are not exposed via this path. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists at this time.

What to do: Upgrade Craft CMS to the latest patched release per the vendor advisory, as the source data does not specify fixed version numbers. In the meantime, audit Control Panel accounts and remove or restrict non-admin users who hold only the accessCp permission, and monitor for unexpected child processes spawned by the PHP web worker.

Affected
Craft CMS
Estimated exposure
largetens of thousands of sites plausibly affected (Craft CMS runs on roughly 100k+ sites per public trackers, with only the subset that has non-admin CP users… — Public web-technology trackers place Craft CMS in the range of on the order of 100,000 live sites, and only deployments that have granted Control Panel access to non-admin accounts with the accessCp permission are exploitable, so a sizable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

Weakness
CWE-470
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.