← back
CVE-2026-79988highCWE-693

Authenticated RCE through Twig sandbox escape

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.7epss 0.3%
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
craftcms · cms