ExploitMatch
Back

CVE-2026-79987

Monitor on ThreatCluster

Description

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.