VYPR
Critical severity9.1NVD Advisory· Published Mar 4, 2026· Updated Jun 17, 2026

CVE-2026-28697

CVE-2026-28697

Description

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., Email Templates). By calling the craft.app.fs.write() method, an attacker can write a malicious PHP script to a web-accessible directory and subsequently access it via the browser to execute arbitrary system commands. This vulnerability is fixed in 4.17.0-beta.1 and 5.9.0-beta.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
craftcms/cmsPackagist
>= 5.0.0-RC1, < 5.9.0-beta.15.9.0-beta.1
craftcms/cmsPackagist
>= 4.0.0-RC1, < 4.17.0-beta.14.17.0-beta.1

Affected products

9
  • Range: >= 5.0.0-RC1, < 5.9.0-beta.1
  • ghsa-coords
    Range: >= 5.0.0-RC1, < 5.9.0-beta.1
  • cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*range: >4.0.0,<4.17.0
    • cpe:2.3:a:craftcms:craft_cms:4.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:craftcms:craft_cms:4.0.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:craftcms:craft_cms:4.0.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:craftcms:craft_cms:4.0.0:rc3:*:*:*:*:*:*
    • cpe:2.3:a:craftcms:craft_cms:5.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:craftcms:craft_cms:5.0.0:rc1:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.