Protection mechanism failure in Craft CMS - #VU139966

 

Protection mechanism failure in Craft CMS - #VU139966

Published: July 29, 2026


Vulnerability identifier: #VU139966
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to a protection mechanism failure in the Twig sandbox SecurityPolicy class when rendering a user-defined Twig template. A remote user can render a malicious Twig template to execute arbitrary code.

Exploitation requires permission to access the control panel, and the issue can be triggered even when the Twig sandbox is enabled through enableTwigSandbox().


Affected software

Craft CMS

Remediation

Install security update from vendor's website.

Craft CMS - addressed in versions 4.18.3, 5.10.7

External References

Related Security Bulletins