CRITICAL
Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates
Published Mar 4, 2026
9.4
CRITICALCVSS 4.0
EPSS 1.14%
Description
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., Email Templates). By calling the craft.app.fs.write() method, an attacker can write a malicious PHP script to a web-accessible directory and subsequently access it via the browser to execute arbitrary system commands. This vulnerability is fixed in 4.17.0-beta.1 and 5.9.0-beta.1.
Affected products
-
- Version >= 4.0.0-RC1, < 4.17.0-beta.1StatusaffectedConstraints-
- Version >= 5.0.0-RC1, < 5.9.0-beta.1StatusaffectedConstraints-
- Version
OR
- > 4.0.0 · < 4.17.0
- > 5.0.0 · < 5.9.0
- 4.0.0
- 4.0.0
- 4.0.0
- 4.0.0
- 5.0.0
- 5.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://github.com/advisories/GHSA-v47q-jxvr-p68x Advisory
- https://github.com/craftcms/cms/commit/9dc2a4a3ec8e9cd5e8c0d1129f36371437519197 x_refsource_MISCPatch
- https://github.com/craftcms/cms/pull/18216 x_refsource_MISCIssue TrackingPatch
- https://github.com/craftcms/cms/pull/18219 x_refsource_MISCIssue TrackingPatch
- https://github.com/craftcms/cms/security/advisories/GHSA-v47q-jxvr-p68x x_refsource_CONFIRMExploitMitigationPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-28697
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-v47q-jxvr-p68x | Advisory | |
| https://github.com/craftcms/cms/commit/9dc2a4a3ec8e9cd5e8c0d1129f36371437519197 | x_refsource_MISCPatch | |
| https://github.com/craftcms/cms/pull/18216 | x_refsource_MISCIssue TrackingPatch | |
| https://github.com/craftcms/cms/pull/18219 | x_refsource_MISCIssue TrackingPatch | |
| https://github.com/craftcms/cms/security/advisories/GHSA-v47q-jxvr-p68x | x_refsource_CONFIRMExploitMitigationPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-28697 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Mar 4, 2026
Updated Mar 6, 2026
Reserved Mar 2, 2026
Link CVE-2026-28697
CISA Vulnrichment
GHSA-V47Q-JXVR-P68X Updated Mar 4, 2026