CVE-2026-28695: Craft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadget
Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the create() Twig function combined with a Symfony Process gadget chain. The create() Twig function exposes Craft::createObject(), which allows instantiation of arbitrary PHP classes with constructor arguments. Combined with the bundled symfony/process dependency, this enables RCE. This bypasses the fix implemented for CVE-2025-57811 (patched in 5.8.7). This vulnerability is fixed in 5.9.0-beta.1 and 4.17.0-beta.1.
Other sources
There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the create() Twig function combined with a Symfony Process gadget chain.
This bypasses the fix implemented for CVE-2025-57811 (patched in 5.8.7).
Required Permissions
- Administrator permissions or access to System Messages utility - allowAdminChanges enabled in production (against our security recommendations) or access to System Messages utility
Vulnerability Details The create() Twig function exposes Craft::createObject(), which allows instantiation of arbitrary PHP classes with constructor arguments. Combined with the bundled symfony/process dependency, this enables RCE.
Attack Vector Admin panel → Settings → Entry Types → Title Format field
Proof of Concept Payload
{% set p = create("Symfony\\Component\\Process\\Process", [["id"]]) %}{{ p.mustRun.getOutput }}
Steps to Reproduce 1. Log in as admin 2. Navigate to Settings → Entry Types 3. Edit any entry type’s "Title Format" field 4. Insert the payload above 5. Create/edit an entry of that type 6. Command executes, output appears in entry title
Impact - Authenticated Remote Code Execution - Runs as web server user (root in default Docker setup) - Full server compromise
Root Cause Craft::createObject() allows the instantiation of any class, including Symfony\Component\Process\Process, which executes shell commands.
Suggested Fix
- Blocklist dangerous classes in createObject() when called from Twig - Or remove/restrict the create() Twig function - Or validate class names against an allowlist
Resources
https://github.com/craftcms/cms/commit/e31e50849ad71638e11ea55fbd1ed90ae8f8f6e0
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28695?
CVE-2026-28695 is considered a critical vulnerability due to its potential for authenticated remote code execution via Server-Side Template Injection.
How do I fix CVE-2026-28695?
To resolve CVE-2026-28695, you need to update Craft CMS to version 4.17.0-beta.1 or 5.9.0-beta.1.
Which versions of Craft CMS are affected by CVE-2026-28695?
CVE-2026-28695 affects Craft CMS versions from 4.0.0-RC1 up to but not including 4.17.0, and from 5.0.0 up to but not including 5.9.0.
What exploit methods exist for CVE-2026-28695?
CVE-2026-28695 can be exploited using authenticated remote code execution via the create() function in Twig combined with a Symfony Process gadget.
How can I determine if my Craft CMS installation is vulnerable to CVE-2026-28695?
You can determine vulnerability by checking if your Craft CMS version is within the affected ranges specified in the CVE report.