Command Injection Vulnerability in Craft CMS Affects Non-Admin Users
CVE-2026-79987
8.7HIGH
What is CVE-2026-79987?
An authenticated user with limited access in Craft CMS can exploit a security flaw, leading to the execution of operating system commands through the PHP web worker. This vulnerability may allow unauthorized actions within the server environment, posing significant risks to application integrity and data security.
Affected Version(s)
cms 5.8.0 < 5.10.13
