
CVE-2026-27127 Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutat… https://www.cve.org/CVERecord?id=CVE-2026-27127
Post summary
The CVE record describes an SSRF vulnerability in Craft CMS’s GraphQL Asset mutation, but provides no PoC, exploit code, active exploitation evidence, or patch information.



