A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 10 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker. | |
| Title | Low-privilege RCE through element-search eager loading | |
| First Time appeared |
Craftcms
Craftcms cms |
|
| Weaknesses | CWE-470 | |
| CPEs | cpe:2.3:a:craftcms:cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Craftcms
Craftcms cms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Hackrate
Published:
Updated: 2026-09-10T16:05:55.403Z
Reserved: 2026-08-25T16:39:03.170Z
Link: CVE-2026-79987
No data.
Status : Received
Published: 2026-09-10T16:17:56.543
Modified: 2026-09-10T16:17:56.543
Link: CVE-2026-79987
No data.
OpenCVE Enrichment
No data.
Weaknesses