SB2026072924 - Protection mechanism failure in Craft CMS



SB2026072924 - Protection mechanism failure in Craft CMS

Published: July 29, 2026

Security Bulletin ID SB2026072924
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Protection mechanism failure (CVE-ID: N/A)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to a protection mechanism failure in the Twig sandbox SecurityPolicy class when rendering a user-defined Twig template. A remote user can render a malicious Twig template to execute arbitrary code.

Exploitation requires permission to access the control panel, and the issue can be triggered even when the Twig sandbox is enabled through enableTwigSandbox().


Remediation

Install update from vendor's website.