Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92592— Craft CMS before 4.18.6 Remote Code Execution via signed cookie

Quick assessment

Affected
craftcms cms
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是对该漏洞描述信息的中文翻译: Craft CMS 版本 4.8.0 至 4.18.5 以及 5.0.0 至 5.10.12 存在一个安全漏洞:在验证带签名的重定向参数时,系统会使用相同的密钥和格式来对攻击者可控的 cookie 进行签名。原因是 HMAC 签名未绑定其用途——Yii 的 是从与签名请求参数所使用的 Craft 派生出来的。 一个经过身份验证、非管理员用户(无需控制面板访问权限)可以通过 端点设置该 cookie,并将签名的数据包移植到重定向参数中。当登录成功时,Craft 验证签名后,会将已认

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92592

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Craft CMS before 4.18.6 Remote Code Execution via signed cookie
Source: CVE Program / CVE List V5
Vulnerability Description
Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound to its purpose (Yii's cookieValidationKey is derived from the same Craft securityKey used for signed request parameters). An authenticated, non-administrator user (Control Panel access is not required) can set the cookie via the license-shun endpoint and transplant the signed envelope into the redirect parameter; on a successful login, Craft validates the signature and renders the authenticated bytes as an unsandboxed Twig template, where Twig's map filter accepts a string callback and allows PHP system() to execute arbitrary operating-system commands as the web-server user. Exploitation requires an account using password authentication without active 2FA, the default request configuration, and availability of PHP system(). The issue is fixed in 4.18.6 and 5.10.13.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1336
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
craftcms cms 4.8.0 ~ 4.18.6 -
craftcms cms 5.0.0 ~ 5.10.13 -

II. Public POCs for CVE-2026-92592

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92592

登录查看更多情报信息。

Vendor Advisories for CVE-2026-92592 (2)

Same Patch Batch · craftcms · 2026-09-16 · 6 CVEs total

CVE-2026-92593 8.8 HIGH Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution
CVE-2026-92594 7.5 HIGH Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL
CVE-2026-92591 5.9 MEDIUM Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer
CVE-2026-92590 5.4 MEDIUM Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields
CVE-2026-92589 4.3 MEDIUM Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder

IV. Related Vulnerabilities

V. Comments for CVE-2026-92592

No comments yet


Leave a comment