Path Traversal Vulnerability in Craft CMS by Pixel & Tonic
CVE-2026-72783

6.9MEDIUM

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72783?

Craft CMS versions ranging from 5.0.0-RC1 to below 5.10.6, as well as from 4.0.0-RC1 to below 4.18.2, exhibit a potential path traversal vulnerability due to the implementation of the 'ensurePathIsContained' function in the Local file system class. The vulnerability arises when the order of operations processes path validation prior to normalization, leading to a scenario where malicious actors could potentially access files outside the intended directory structure. Although the vendor has indicated that the vulnerability is not directly exploitable and no attacks have been discovered to take advantage of it, applying the recommended fixes is crucial to enhance system integrity and harden security.

Affected Version(s)

cms 5.0.0-RC1 < 5.10.6

cms 4.0.0-RC1 < 4.18.2

cms 5.10.6

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.