Description
Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in Cp::elementLabelHtml(). Because Craft/Yii HMAC tokens are not bound to a parameter name, an authenticated low-privilege control panel user with edit rights on a single element type can mint a token over attacker-controlled Twig for the returnUrl parameter and replay it as the redirect POST parameter, reaching the unsandboxed sink and achieving server-side template injection that executes arbitrary PHP code (full server compromise). The issue is fixed in 5.10.13.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix that permits server‑side template injection. An authenticated low‑privilege control panel user who has editing rights on a single element type can craft a self‑signed HMAC token that contains attacker‑controlled Twig code for the returnUrl parameter. The token can be replayed as a redirect POST parameter, reaching an unsandboxed Twig sink in View::renderObjectTemplate() and allowing execution of arbitrary PHP code on the server, effectively giving full server compromise.

Affected Systems

Craft CMS 5.10.0 to 5.10.12 from CraftCMS. The affected versions are those prior to 5.10.13, according to the advisory.

Risk and Exploitability

The CVSS score is 8.7, indicating a high‑severity flaw. The EPSS score is reported as less than 1 %, showing a very low probability of real‑world exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with edit permissions on an element type, so attackers must first compromise a legitimate user account with at least that level of access. Once the conditions are met, the attacker can replay the forged HMAC token to trigger the unsandboxed Twig sink and execute code on the server.

Generated by OpenCVE AI on September 17, 2026 at 21:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Craft CMS 5.10.13 patch or later to fully address the issue.
  • If patching is not immediately possible, remove edit permissions from the affected element type to prevent an authenticated user from creating the necessary token.
  • Validate or sanitize the returnUrl parameter before passing it to Twig rendering to block injection attempts.

Generated by OpenCVE AI on September 17, 2026 at 21:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in Cp::elementLabelHtml(). Because Craft/Yii HMAC tokens are not bound to a parameter name, an authenticated low-privilege control panel user with edit rights on a single element type can mint a token over attacker-controlled Twig for the returnUrl parameter and replay it as the redirect POST parameter, reaching the unsandboxed sink and achieving server-side template injection that executes arbitrary PHP code (full server compromise). The issue is fixed in 5.10.13.
Title Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution
First Time appeared Craftcms
Craftcms craft Cms
Weaknesses CWE-94
CPEs cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms
Craftcms craft Cms
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Craftcms Craft Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:45:54.536Z

Reserved: 2026-09-16T13:47:49.170Z

Link: CVE-2026-92593

cve-icon Vulnrichment

Updated: 2026-09-17T14:45:49.997Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T22:18:30.150

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92593

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:15:13Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')