GHSA-fpmm-w3hp-7f39HighCVSS 8.8

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission...

Published
September 10, 2026
Last Modified
September 10, 2026

🔗 CVE IDs covered (1)

📋 Description

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

🔗 References (6)