CVE-2026-79987 HIGH

CVE-2026-79987: Low-privilege RCE through element-search eager loading

Vendor Craftcms
Product cms
Weakness CWE-470
Published September 10, 2026
Last update September 11, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

Key dates

02Disclosure timeline

September 10, 2026 CVE published
September 11, 2026 Record updated