CVE-2026-79987: Craft CMS CMS
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.
Affected products
- Craft CMS CMS: from 5.8.0, before 5.10.13 (fixed in 5.10.13)
Published 2026-09-10. Last modified 2026-09-11.