PT-2026-70197 · Craft Cms · Craft Cms

·

CVE-2026-72779

·

Published

2026-08-06

·

Updated

2026-08-11

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Craft CMS versions 5.0.0-RC1 through 5.10.5 Craft CMS versions 4.0.0-RC1 through 4.18.1
Description An arbitrary file read issue exists where the create() Twig function fails to include SplFileObject in its class instantiation blocklist. This allows an authenticated administrator with allowAdminChanges=true to configure a malicious entry type title or URI format that instantiates SplFileObject within a non-sandboxed template context. Consequently, when a user creates an entry in the affected section, sensitive server files, such as the .env file containing security keys and database credentials, can be read and rendered as entry titles.
Recommendations Update Craft CMS versions 5.0.0-RC1 through 5.10.5 to version 5.10.6. Update Craft CMS versions 4.0.0-RC1 through 4.18.1 to version 4.18.2.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72779
GHSA-2P2V-3MJG-GFPF
GHSA-957R-QF9P-67XW

Affected Products

Craft Cms