Authenticated Remote Code Execution in Craft CMS by Craft
CVE-2026-92593

8.7HIGH

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92593?

Craft CMS versions 5.10.0 to 5.10.12 are vulnerable to an authenticated remote code execution attack due to an incomplete fix related to a previous security issue. The flaw exists in the process of handling redirect URLs, where a low-privilege control panel user with edit rights can exploit this vulnerability. Specifically, the unsandboxed execution of PHP code occurs through the use of attacker-controlled Twig templates, allowing for the potential full compromise of the server. This vulnerability has been addressed in version 5.10.13.

Affected Version(s)

cms 5.10.0 < 5.10.13

cms 5.10.13

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.