CVE-2026-27128: Craft CMS's race condition in Token Service potentially allows for token usage greater than the token limit

Published Feb 23, 2026
·
Updated

A Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validation service for tokens that explicitly set a limited usage. The getTokenRoute() method reads a token’s usage count, checks if it’s within limits, then updates the database in separate non-atomic operations. By sending concurrent requests, an attacker can use a single-use impersonation token multiple times before the database update completes.

To make this work, an attacker needs to obtain a valid user account impersonation URL with a non-expired token via some other means and exploit a race condition while bypassing any rate-limiting rules in place.

For this to be a privilege escalation, the impersonation URL must include a token for a user account with more permissions than the current user.

References

https://github.com/craftcms/cms/commit/3e4afe18279951c024c64896aa2b93cda6d95fdf

Other sources

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validation service for tokens that explicitly set a limited usage. The getTokenRoute() method reads a token’s usage count, checks if it’s within limits, then updates the database in separate non-atomic operations. By sending concurrent requests, an attacker can use a single-use impersonation token multiple times before the database update completes. To make this work, an attacker needs to obtain a valid user account impersonation URL with a non-expired token via some other means and exploit a race condition while bypassing any rate-limiting rules in place. For this to be a privilege escalation, the impersonation URL must include a token for a user account with more permissions than the current user. Versions 4.16.19 and 5.8.23 patch the issue.

MITRE

Affected Software

8 affected componentsFixes available
composer/craftcms/cms>=5.0.0-RC1<=5.8.22
5.8.23
composer/craftcms/cms>=4.5.0-RC1<=4.16.18
4.16.19
CraftCMS Craft CMS>4.5.0<4.16.19
CraftCMS Craft CMS>5.0.0<5.8.23
CraftCMS Craft CMS=4.5.0
CraftCMS Craft CMS=4.5.0-rc1
CraftCMS Craft CMS=5.0.0
CraftCMS Craft CMS=5.0.0-rc1

Event History

Feb 23, 2026
Advisory Published
via GitHub·10:16 PM
Data Sourced
via GitHub·10:16 PM
DescriptionWeaknessAffected Software
Feb 24, 2026
CVE Published
via MITRE·02:42 AM
Data Sourced
via MITRE·02:42 AM
DescriptionWeakness
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 AM
RemedyAffected Software
Jan 4, 58137
Event
via FIRST·02:39 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-27128?

CVE-2026-27128 has been rated as a high severity vulnerability due to its potential impact on token usage integrity.

2

How do I fix CVE-2026-27128?

To fix CVE-2026-27128, upgrade Craft CMS to version 5.8.23 or 4.16.19.

3

Which versions are affected by CVE-2026-27128?

CVE-2026-27128 affects Craft CMS versions between 5.0.0-RC1 and 5.8.22, as well as versions between 4.5.0-RC1 and 4.16.18.

4

What impact does CVE-2026-27128 have on my Craft CMS installation?

CVE-2026-27128 could lead to unauthorized token usage through a race condition issue.

5

Is there a workaround for CVE-2026-27128 before upgrading?

While immediate fixes are not provided, limiting access to the token validation service may help minimize risk until an upgrade is performed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203