Remote Code Execution Vulnerability in Craft CMS by Pixel & Tonic
CVE-2026-72781

8.7HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72781?

Craft CMS versions 5.0.0-RC1 and earlier than 5.10.7, and versions 4.0.0-RC1 and earlier than 4.18.3 are susceptible to a remote code execution vulnerability due to weaknesses in the Twig sandbox mechanism. An authenticated attacker with access to the control panel can exploit this vulnerability by leveraging the ElementInterface's AllowedInSandbox attribute. This allows for the execution of arbitrary code through crafted Twig templates, even when the Twig sandbox functionality is enabled. It is crucial to apply the necessary updates to mitigate this risk.

Affected Version(s)

cms 5.0.0-RC1 < 5.10.7

cms 4.0.0-RC1 < 4.18.3

cms 5.10.7

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.