CVE-2026-55794Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with the ability to edit entries can execute unsandboxed Twig code via the HTTP Referrer header, potentially leading to authenticated RCE. The issue happens when a user is saving entries. Strings for a signed redirect URL are being compiled as a Twig template via renderObjectTemplate(), and while a sandboxed alternative already exists (renderSandboxedObjectTemplate()), it is not used in this case. This signed URL can be specified by users, as it is reflected in the “Referer” HTTP request header, which is under attacker control. This issue has been fixed in version 5.10.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-1336

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-02); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-02: 2Mentions · 2026-09-16: 1Technical Details · 2026-07-02: 2Technical Details · 2026-09-16: 107-0209-16
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-022
Disclosure2
2026-09-161
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-92593 Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink re… https://www.cve.org/CVERecord?id=CVE-2026-92593

    Post summary

    The text discloses CVE-2026-92593 as an incomplete fix for CVE-2026-55794 affecting Craft CMS versions 5.10.0–5.10.12, providing technical vulnerability details but no PoC, exploit, active exploitation claim, or named remediation.

    000101.3K
    58.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-55794 Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with the ability to edit entries can execute unsandbo… https://www.cve.org/CVERecord?id=CVE-2026-55794 ----- Traducción: CVE-2026-55794 Cra… http://infoflow.cloud`

    Post summary

    CVE-2026-55794 exposes unsandboxed code execution in Craft CMS versions 5.9.0–5.9.x for users with entry-editing privileges, based on the public CVE record; no exploitation or patch details are noted.

    0000033
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-55794 Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with the ability to edit entries can execute unsandbo… https://www.cve.org/CVERecord?id=CVE-2026-55794

    Post summary

    The post provides a brief disclosure of CVE‑2026‑55794, stating that Craft CMS privilege escalation allows unsandboxed code execution for editors in versions 5.9.0–5.9.x, but no proof‑of‑concept, exploit, patch, or active exploitation details are included.

    00000748
    57.7K followersView on X

Explore more