Authenticated Remote Code Execution in Craft CMS by Craft
CVE-2026-92593
8.7HIGH
What is CVE-2026-92593?
Craft CMS versions 5.10.0 to 5.10.12 are vulnerable to an authenticated remote code execution attack due to an incomplete fix related to a previous security issue. The flaw exists in the process of handling redirect URLs, where a low-privilege control panel user with edit rights can exploit this vulnerability. Specifically, the unsandboxed execution of PHP code occurs through the use of attacker-controlled Twig templates, allowing for the potential full compromise of the server. This vulnerability has been addressed in version 5.10.13.
Affected Version(s)
cms 5.10.0 < 5.10.13
cms 5.10.13
