Executive brief
Craft CMS is a popular open-source content management system used to build custom websites and applications. An authenticated user with only basic Control Panel access can execute arbitrary operating system commands with the privileges of the web server process, potentially compromising the entire server and all data hosted on it.
Technical details
This vulnerability allows a remote, authenticated, non-admin user with only the accessCp permission to execute arbitrary operating system commands in the context of the PHP web worker. The attack requires network access to the Craft CMS Control Panel and valid authentication credentials, but no elevated administrative privileges. An attacker exploiting this flaw can achieve remote code execution (RCE) with the permissions of the web server process, enabling data theft, malware installation, lateral movement, and service disruption. Patches are available; administrators should update to a patched version immediately.
Affected products
- Craft CMS CMS <UNKNOWN>
Timeline
- 2026-09-10: disclosed