Improper Neutralization of Special Elements Used in a Template Engine in Craft CMS - CVE-2026-28697
Published: June 16, 2026
Craft CMS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements used in a template engine in Twig template fields when rendering attacker-controlled template content. A remote user can inject a server-side template injection payload that writes a malicious PHP script to a web-accessible directory to execute arbitrary code.
Exploitation requires access to an authenticated administrator account with allowAdminChanges enabled, or access to the System Messages utility.