Remote Code Execution Vulnerability in Craft CMS by Craft CMS
CVE-2026-92592

8.7HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92592?

Craft CMS versions 4.8.0 to 4.18.5 and 5.0.0 to 5.10.12 contain a vulnerability that allows authenticated users to exploit signed cookies. Attackers can manipulate a license-shun cookie, leveraging an improper HMAC key that isn't bound to its intended purpose. By transferring this signed cookie into the redirect parameter upon a successful login, the attacked server can execute arbitrary system commands through unsanitized output within a Twig template. Successful exploitation requires a user account with password authentication and the absence of two-factor authentication (2FA), alongside the capability to invoke PHP system(). The vulnerability has been addressed in versions 4.18.6 and 5.10.13.

Affected Version(s)

cms 4.8.0 < 4.18.6

cms 5.0.0 < 5.10.13

cms 4.18.6

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Crypto-Cat
.