Remote Code Execution Vulnerability in Craft CMS by Craft
CVE-2026-28695

7.5HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
4 March 2026

What is CVE-2026-28695?

Craft CMS suffers from a Remote Code Execution vulnerability due to an authenticated admin exploit via Server-Side Template Injection. This flaw arises from the use of the create() Twig function, which allows attackers to instantiate arbitrary PHP classes, leveraging the Symfony Process component. The attack method bypasses previous security measures implemented for earlier vulnerabilities, providing an opportunity for unauthorized command execution. This issue has been addressed in versions 5.9.0-beta.1 and 4.17.0-beta.1, urging users to upgrade their installations for enhanced security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

cms >= 5.8.7, < 5.9.0-beta.1 < 5.8.7, 5.9.0-beta.1

cms >= 4.0.0-RC1, < 4.17.0-beta.1 < 4.0.0-RC1, 4.17.0-beta.1

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.