CVE-2026-79988

Severity CVSS v4.0:
HIGH
Type:
CWE-693 Protection Mechanism Failure
Publication date:
27/08/2026
Last modified:
28/08/2026

Description

The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.