The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-27 17:20
Updated : 2026-08-28 20:20
NVD link : CVE-2026-79988
Mitre link : CVE-2026-79988
CVE.ORG link : CVE-2026-79988
JSON object : View
Products Affected
No product.
CWE
CWE-693
Protection Mechanism Failure
