PT-2026-5681 · Crafter · Crafter Cms+1

Published

2026-02-02

·

Updated

2026-05-06

·

CVE-2026-1770

CVSS v4.0

4.5

Medium

VectorAV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:H/SI:H/SA:H/E:U
Name of the Vulnerable Software and Affected Versions Crafter CMS versions (affected versions not specified)
Description An issue exists in Crafter Studio of Crafter CMS that allows authenticated developers to execute operating system commands. This is due to a bypass of the Groovy Sandbox restrictions, enabling the execution of malicious Groovy elements and potentially leading to Remote Code Execution (RCE).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-1770
GHSA-GJ28-GW7W-3PXC

Affected Products

Crafter Cms
Crafter Studio