Remote Code Execution Vulnerability in Craft CMS by Craft CMS
CVE-2026-92592
What is CVE-2026-92592?
Craft CMS versions 4.8.0 to 4.18.5 and 5.0.0 to 5.10.12 contain a vulnerability that allows authenticated users to exploit signed cookies. Attackers can manipulate a license-shun cookie, leveraging an improper HMAC key that isn't bound to its intended purpose. By transferring this signed cookie into the redirect parameter upon a successful login, the attacked server can execute arbitrary system commands through unsanitized output within a Twig template. Successful exploitation requires a user account with password authentication and the absence of two-factor authentication (2FA), alongside the capability to invoke PHP system(). The vulnerability has been addressed in versions 4.18.6 and 5.10.13.
Affected Version(s)
cms 4.8.0 < 4.18.6
cms 5.0.0 < 5.10.13
cms 4.18.6
