CVE-2026-27128Disclosure(craftcms / craft_cms)

LOWCVSS 4.8 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validation service for tokens that explicitly set a limited usage. The `getTokenRoute()` method reads a token’s usage count, checks if it’s within limits, then updates the database in separate non-atomic operations. By sending concurrent requests, an attacker can use a single-use impersonation token multiple times before the database update completes. To make this work, an attacker needs to obtain a valid user account impersonation URL with a non-expired token via some other means and exploit a race condition while bypassing any rate-limiting rules in place. For this to be a privilege escalation, the impersonation URL must include a token for a user account with more permissions than the current user. Versions 4.16.19 and 5.8.23 patch the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • craft_cms

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
craft_cms

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-24: 3Technical Details · 2026-02-24: 302-24
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27128 Time-of-Check-Time-of-Use Race Condition in Craft CMS Token Validation Service https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27128

    Post summary

    A new CVE (CVE-2026-27128) describing a TOCTOU race condition in Craft CMS's token validation service has been disclosed, with details available via the provided link.

    0000153
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27128 Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-of-Check-Time-of-Use (TOCTOU) race condition ex… https://www.cve.org/CVERecord?id=CVE-2026-27128

    Post summary

    The text announces a TOCTOU race condition vulnerability in Craft CMS (CVE‑2026‑27128) but provides no PoC, exploit, or patch details.

    0000081
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27128: Crafty Concurrency: Smashing the Token Limit in Craft CMS A classic Time-of-Check Time-of-Use (TOCTOU) race condition in Craft CMS allows attackers to bypass usage limits on sensitive tokens. By flooding the server with concurrent requ... https://cvereports.com/reports/CVE-2026-27128

    Post summary

    The report describes a TOCTOU race condition in Craft CMS that lets attackers bypass token usage limits by flooding the server with concurrent requests.

    0000044
    31 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appcraftcmscraft_cms---
Appcraftcmscraft_cms4.5.0--
Appcraftcmscraft_cms4.5.0--
Appcraftcmscraft_cms5.0.0--
Appcraftcmscraft_cms5.0.0--

Explore more