CVE-2026-79988: Authenticated RCE through Twig sandbox escape
Published Aug 27, 2026
·Updated
The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.
Affected Software
1 affected component
Craft CMS Craft CMS
Event History
Aug 27, 2026
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
DescriptionWeakness
Data Sourced
via NVD·05:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is authenticated, so the attacker needs valid access to the affected Craft CMS instance. The provided information does not specify which user roles or permissions are sufficient.
2
What is the impact after successful exploitation?
Successful exploitation can result in remote code execution through an escape from the Twig sandbox. This could allow code to run on the Craft CMS server in the context of the application.
3
Which release should be reviewed for a fix?
The supplied references include the Craft CMS 5.10.7 release. Review that release and the associated release notes to determine the applicable remediation for your deployment.