Improper Neutralization of Special Elements Used in a Template Engine in Craft CMS - CVE-2026-28697

 

Improper Neutralization of Special Elements Used in a Template Engine in Craft CMS - CVE-2026-28697

Published: June 16, 2026


Vulnerability identifier: #VU134655
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-28697
CWE-ID: CWE-1336
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper neutralization of special elements used in a template engine in Twig template fields when rendering attacker-controlled template content. A remote user can inject a server-side template injection payload that writes a malicious PHP script to a web-accessible directory to execute arbitrary code.

Exploitation requires access to an authenticated administrator account with allowAdminChanges enabled, or access to the System Messages utility.


Affected software

Craft CMS

How to mitigate CVE-2026-28697

Install security update from vendor's website.

Craft CMS - addressed in versions 4.17.0, 5.9.0

External References

Related Security Bulletins