{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/craft-cms--5.11.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-92592"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Craft CMS (4.8.0-4.18.5, 5.0.0-5.10.12)","Craft CMS (\u003c 5.11.0)"],"_cs_severities":["high"],"_cs_tags":["cve","authorization","graphql","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Craft CMS"],"content_html":"\u003cp\u003eCraft CMS versions 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 are susceptible to a remote code execution vulnerability identified as CVE-2026-92592. The issue stems from the application using the same securityKey to sign both internal license-shun cookies and redirect parameters without binding the HMAC signature to a specific purpose.\u003c/p\u003e\n\u003cp\u003eAn authenticated user, even without Control Panel administrative privileges, can manipulate the license-shun cookie and transplant the resulting signed data into a redirect parameter. When the user logs in, Craft CMS validates the signature and subsequently renders the attacker-controlled bytes as an unsandboxed Twig template. By leveraging Twig's map filter, the attacker can invoke PHP's system() function to execute arbitrary commands on the underlying host as the web-server user. Exploitation requires an authenticated account without active 2FA. The vendor has addressed this in Craft CMS versions 4.18.6 and 5.10.13.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the target Craft CMS instance using standard credentials (2FA must be disabled).\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the license-shun endpoint to set a malicious, attacker-controlled cookie.\u003c/li\u003e\n\u003cli\u003eAttacker extracts the signed signature from the license-shun cookie value.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a redirect parameter containing an embedded Twig template payload utilizing the map filter and PHP system() function.\u003c/li\u003e\n\u003cli\u003eAttacker replaces the signature of the redirect parameter with the one harvested from the license-shun cookie.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a login or redirect flow that processes the malicious parameter.\u003c/li\u003e\n\u003cli\u003eCraft CMS validates the HMAC signature, treats the parameter as trusted, and renders the content via the Twig engine.\u003c/li\u003e\n\u003cli\u003eTwig engine executes the PHP system() function, resulting in arbitrary code execution on the server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full remote code execution under the privileges of the web-server process. This allows attackers to gain persistent access, exfiltrate sensitive site data, modify content, or pivot into the underlying server network. The vulnerability impacts all environments running the affected versions that allow non-admin authentication.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade to Craft CMS 4.18.6 or 5.10.13 immediately to remediate CVE-2026-92592.\u003c/li\u003e\n\u003cli\u003eEnforce multi-factor authentication (MFA) for all user accounts to mitigate the prerequisite of successful authentication for this attack.\u003c/li\u003e\n\u003cli\u003eAudit webserver access logs for anomalous POST requests to the license-shun endpoint or unusual GET requests containing serialized data or Twig syntax within redirect parameters.\u003c/li\u003e\n\u003cli\u003eRestrict access to the Craft CMS control panel and related administrative endpoints to authorized IP ranges.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-16T23:53:20Z","date_published":"2026-09-16T23:53:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-craft-cms-rce/","summary":"Craft CMS versions 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 contain a critical vulnerability allowing authenticated users to achieve remote code execution by injecting malicious payloads into improperly validated redirect parameters.","title":"Remote Code Execution in Craft CMS via HMAC Signature Misuse","url":"https://feed.craftedsignal.io/briefs/2026-09-craft-cms-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Craft CMS (\u003c 5.11.0)","version":"https://jsonfeed.org/version/1.1"}