CVE-2026-79987 Details
Description
A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.
A remote, authenticated, non-admin user in the Craft CMS Control Panel can execute operating system commands as the PHP web worker. This vulnerability exists in Craft CMS versions 5.8.0 prior to 5.10.13. The issue arises in the ElementSearchController's actionSearch method, where user-controlled input is not properly sanitized before being executed as a PHP callback. Exploitation does not require admin rights or special permissions, and can be carried out by any user with access to the Control Panel.
Users can update to Craft CMS version 5.10.13 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 10, 2026CISA-ADP
Assessed Sep 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/craftcms/cms | Hackrate | Source CodeVendor |
| https://github.com/craftcms/cms/releases/tag/5.10.13 | Hackrate | Release NotesVendor |
| https://github.com/craftcms/cms/security/advisories/GHSA-9c4j-cjw3-r3xx | Hackrate | AdvisoryVendor |
| https://www.hckrt.com/hacktivity/HCKRT-9TSYY2 | Hackrate | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-470 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | Hackrate |
Affected Products
| Product | Versions |
|---|---|
| Craft CMS | >= 5.8.0, < 5.10.13 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | CISA-ADP |
| Sep 10, 2026 | CVE Modified | CISA-ADP |
| Sep 10, 2026 | New CVE Received | Hackrate |
Volerion