CVE-2026-79987
HIGH
NVD
CVSS Score
8.8
Severity
HIGH
Published
Sep 10, 2026
Vendor
unknown
Description
A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.