PT-2026-94109 · Craft Cms · Craft Cms

·

CVE-2026-92592

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Craft CMS versions 4.8.0 through 4.18.5 Craft CMS versions 5.0.0 through 5.10.12
Description An issue exists where the software signs an authenticated user's attacker-controlled license-shun cookie using the same key and format used to validate signed redirect parameters. This occurs because the HMAC signature is not bound to its purpose, as the cookieValidationKey is derived from the same securityKey used for signed request parameters. An authenticated, non-administrator user can set the cookie via the license-shun endpoint and transplant the signed envelope into the redirect parameter. Upon a successful login, the system validates the signature and renders the authenticated bytes as an unsandboxed Twig template. Within this template, the map filter accepts a string callback, allowing the system() function to execute arbitrary operating-system commands as the web-server user. Exploitation requires an account using password authentication without active 2FA, the default request configuration, and the availability of the PHP system() function.
Recommendations Update Craft CMS versions 4.8.0 through 4.18.5 to version 4.18.6. Update Craft CMS versions 5.0.0 through 5.10.12 to version 5.10.13.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92592
GHSA-5R92-75J8-C534

Affected Products

Craft Cms