MEDIUMVulnerability

CVE-2026-72779

Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create() Twig function restricts class instantiation using a 5-entry blocklist that does not include SplFileObject, allowing an authenticated administrator (with allowAdminChanges=true) to configure a malicious entry type title or URI format that instantiates SplFileObject in a non-sandboxed template context. When a user subsequently creates an entry in the affected section, arbitrary files on the server (such as .env containing the security key and database credentials) are read and rendered as entry titles.

Properties

severity
MEDIUM
score
4.5
epss_score
0.00218
cve_id
CVE-2026-72779
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
published_at
2026-08-11T13:19:08.360
last_modified
2026-09-08T20:32:39.347
epss_percentile
0.12118

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Incomplete List of Disallowed Inputs

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72779 — Ninja Signal Threat Intelligence | Ninja Signal