Remote Code Execution Vulnerability in Craft CMS by Pixel & Tonic
CVE-2026-72781
8.7HIGH
What is CVE-2026-72781?
Craft CMS versions 5.0.0-RC1 and earlier than 5.10.7, and versions 4.0.0-RC1 and earlier than 4.18.3 are susceptible to a remote code execution vulnerability due to weaknesses in the Twig sandbox mechanism. An authenticated attacker with access to the control panel can exploit this vulnerability by leveraging the ElementInterface's AllowedInSandbox attribute. This allows for the execution of arbitrary code through crafted Twig templates, even when the Twig sandbox functionality is enabled. It is crucial to apply the necessary updates to mitigate this risk.
Affected Version(s)
cms 5.0.0-RC1 < 5.10.7
cms 4.0.0-RC1 < 4.18.3
cms 5.10.7
