VYPR
High severity8.8NVD Advisory· Published Sep 10, 2026

CVE-2026-79987

CVE-2026-79987

Description

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

Affected products

2
  • Craftcms/CMSreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.