Description
Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound to its purpose (Yii's cookieValidationKey is derived from the same Craft securityKey used for signed request parameters). An authenticated, non-administrator user (Control Panel access is not required) can set the cookie via the license-shun endpoint and transplant the signed envelope into the redirect parameter; on a successful login, Craft validates the signature and renders the authenticated bytes as an unsandboxed Twig template, where Twig's map filter accepts a string callback and allows PHP system() to execute arbitrary operating-system commands as the web-server user. Exploitation requires an account using password authentication without active 2FA, the default request configuration, and availability of PHP system(). The issue is fixed in 4.18.6 and 5.10.13.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Craft CMS versions 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign authenticated user cookies with a key shared for signed redirect parameters. When an attacker whose account is not an administrator sets a signed cookie via the license‑shun endpoint, the system accepts the cookie's multipart content, rewrites it into a redirect parameter, and upon a successful login it renders the signed data as a Twig template. Twig’s map filter permits a string callback whereby PHP’s system() is invoked, allowing an attacker to execute arbitrary operating‑system commands as the web‑server user. The vulnerability therefore enables remote code execution without requiring administrative privileges, provided the attacker has a password‑authenticated account without active 2FA and standard request configuration.

Affected Systems

Craft CMS server installations running any of the following versions are affected: Craft CMS 4.8.0 through 4.18.5 inclusive, and Craft CMS 5.0.0 through 5.10.12 inclusive. The issue was introduced in 4.8.0 and 5.0.0 and remediated in versions 4.18.6 and 5.10.13 respectively.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability; the EPSS score is below 1%, suggesting current exploitation activity is rare, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is remote via the web interface: an attacker can create or use a normal account, exploit the license‑shun endpoint to craft a signed cookie, then trigger a login that causes Craft to validate and render the cookie’s content as part of a Twig template. Successful exploitation would give the attacker operating‑system command execution as the web‑server process, enabling full compromise of the affected system. The lack of administrative privilege requirement means any user can perform this attack, widening its potential impact.

Generated by OpenCVE AI on September 18, 2026 at 05:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Craft CMS to version 4.18.6 or later, or 5.10.13 or later, which fixes the improper binding of the HMAC signature.
  • Disable or restrict access to the license‑shun endpoint so that non‑administrator users cannot set the signed cookie.
  • Enable two‑factor authentication for all accounts so that attackers cannot rely solely on password authentication to gain a session that can be exploited.

Generated by OpenCVE AI on September 18, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Craftcms cms
Vendors & Products Craftcms cms

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound to its purpose (Yii's cookieValidationKey is derived from the same Craft securityKey used for signed request parameters). An authenticated, non-administrator user (Control Panel access is not required) can set the cookie via the license-shun endpoint and transplant the signed envelope into the redirect parameter; on a successful login, Craft validates the signature and renders the authenticated bytes as an unsandboxed Twig template, where Twig's map filter accepts a string callback and allows PHP system() to execute arbitrary operating-system commands as the web-server user. Exploitation requires an account using password authentication without active 2FA, the default request configuration, and availability of PHP system(). The issue is fixed in 4.18.6 and 5.10.13.
Title Craft CMS before 4.18.6 Remote Code Execution via signed cookie
First Time appeared Craftcms
Craftcms craft Cms
Weaknesses CWE-1336
CPEs cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms
Craftcms craft Cms
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:23:31.247Z

Reserved: 2026-09-16T13:47:49.170Z

Link: CVE-2026-92592

cve-icon Vulnrichment

Updated: 2026-09-17T18:57:23.931Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T22:18:30.013

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92592

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:15:03Z

Weaknesses
  • CWE-1336

    Improper Neutralization of Special Elements Used in a Template Engine