216.73.217.22

CVE-2026-28695

· Published 04/03/2026 17:16 · Modified 05/03/2026 19:54

Labels: CVE-2026-28695 2026-03-04CVE-2026-28695CWE-1336[email protected]

Essential information

Published
04/03/2026 17:16
Modified
05/03/2026 19:54
Author
Creator
CVSS
7.5 HIGH (v3) 7.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the create() Twig function combined with a Symfony Process gadget chain. The create() Twig function exposes Craft::createObject(), which allows instantiation of arbitrary PHP classes with constructor arguments. Combined with the bundled symfony/process dependency, this enables RCE. This bypasses the fix implemented for CVE-2025-57811 (patched in 5.8.7). This vulnerability is fixed in 5.9.0-beta.1 and 4.17.0-beta.1.

NVD status

Status
Analyzed — CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
craftcms / craft cms cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
craftcms / craft cms cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
craftcms / craft cms cpe:2.3:a:craftcms:craft_cms:4.0.0:-:*:*:*:*:*:*
craftcms / craft cms cpe:2.3:a:craftcms:craft_cms:4.0.0:rc1:*:*:*:*:*:*
craftcms / craft cms cpe:2.3:a:craftcms:craft_cms:4.0.0:rc2:*:*:*:*:*:*
craftcms / craft cms cpe:2.3:a:craftcms:craft_cms:4.0.0:rc3:*:*:*:*:*:*
craftcms / craft cms cpe:2.3:a:craftcms:craft_cms:5.0.0:-:*:*:*:*:*:*
craftcms / craft cms cpe:2.3:a:craftcms:craft_cms:5.0.0:rc1:*:*:*:*:*:*

References