PT-2026-94110 · Craft Cms · Craft Cms

CVE-2026-92593

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Craft CMS versions 5.10.0 through 5.10.12
Description An authenticated low-privilege control panel user with edit rights on a single element type can achieve server-side template injection, leading to arbitrary PHP code execution and full server compromise. This occurs because the Controller::getPostedRedirectUrl() to View::renderObjectTemplate() sink remains unsandboxed and a self-signing oracle exists in Cp::elementLabelHtml(). Since Craft/Yii HMAC tokens are not bound to a parameter name, an attacker can mint a token for the returnUrl parameter and replay it as the redirect POST parameter to reach the unsandboxed sink.
Recommendations Update Craft CMS to version 5.10.13.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92593
GHSA-5JMW-G85V-7JV2

Affected Products

Craft Cms