CVE-2026-79987
EUVD-2026-7558610.09.2026, 16:17
A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.
Awaiting analysis
This vulnerability is currently awaiting analysis.