Impact
The vulnerability allows an authenticated non‑admin Craft CMS Control Panel user possessing only the accessCp permission to execute arbitrary operating system commands through the PHP web worker. This remote command execution can lead to full system compromise, enabling attackers to exfiltrate data, install backdoors, or pivot to other systems. The weakness is identified as CWE‑470, reflecting unsafe use of PHP exec functionality.
Affected Systems
Craft CMS Control Panel users with the accessCp permission are affected. The specific product is Craft CMS; version details are not provided in the CNA data, so administrators should verify that the instance is running a version prior to the latest release 5.10.13, which contains the patch.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score is not available, so deception of exploitation likelihood is unknown; however, the vulnerability requires only Control Panel login, which is commonly exposed. The flaw is not listed in CISA KEV, but its the vulnerable PHP worker to run commands remotely once authenticated, without additional privilege escalation.
OpenCVE Enrichment