CVE-2026-79987: Craft CMS CMS

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

Affected products

  • Craft CMS CMS: from 5.8.0, before 5.10.13 (fixed in 5.10.13)

Published 2026-09-10. Last modified 2026-09-11.