SB2026072924 - Protection mechanism failure in Craft CMS
Published: July 29, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Protection mechanism failure (CVE-ID: N/A)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to a protection mechanism failure in the Twig sandbox SecurityPolicy class when rendering a user-defined Twig template. A remote user can render a malicious Twig template to execute arbitrary code.
Exploitation requires permission to access the control panel, and the issue can be triggered even when the Twig sandbox is enabled through enableTwigSandbox().
Remediation
Install update from vendor's website.