CVE-2026-28783Disclosure(craftcms / craft_cms)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch craftcms craft_cms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Closure arrow functions. In order to be able to successfully execute this attack, you need to either have allowAdminChanges enabled on production, or a compromised admin account, or an account with access to the System Messages utility. Several PHP functions are not included in the blocklist, which could allow malicious actors with the required permissions to execute various types of payloads, including RCEs, arbitrary file reads, SSRFs, and SSTIs. This vulnerability is fixed in 5.9.0-beta.1 and 4.17.0-beta.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-184CWE-1336

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • craft_cms

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
craft_cms

2 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-04: 1Patch / Workaround · 2026-03-04: 103-04
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2026-28783 Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions f… https://www.cve.org/CVERecord?id=CVE-2026-28783

    Post summary

    The passage describes CVE‑2026‑28783, noting a blocklist flaw in Craft CMS and indicating that versions 5.9.0‑beta.1 and 4.17.0‑beta.1 include a fix.

    00000215
    56.6K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appcraftcmscraft_cms---
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms5.0.0--
Appcraftcmscraft_cms5.0.0--

Explore more