CVE-2026-72783
Craft CMS vulnerability analysis and mitigation

Overview

CVE-2026-72783 is a theoretical path traversal weakness (CWE-22) in Craft CMS affecting the ensurePathIsContained function of the Local file system class. It affects Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2. The vulnerability was published on August 11, 2026, with the vendor's own security advisory (GHSA-7hxc-f267-h5q7) originally published July 25, 2026. The CVSS v3.1 base score is 6.2 (Medium), and the CVSS v4.0 base score is 6.9 (Medium) (GitHub Advisory, Github Advisory).

Technical details

The root cause is a desanitization-style ordering flaw (CWE-22) in the ensurePathIsContained function within Craft CMS's Local file system class. When an asset file is read, the getFileStream method constructs a file path by first validating the input path, then normalizing it, and finally prepending the volume's base directory prefix. Because normalization occurs after validation, a crafted path could pass the initial validation check but, after normalization (e.g., resolving ../ sequences or encoded characters), resolve to a location outside the intended volume directory. The vendor explicitly notes that no directly exploitable scenario has been identified, and the fix is recommended purely as a hardening measure (GitHub Advisory, Github Advisory).

Impact

If theoretically exploited, the vulnerability could allow an attacker with local access to read sensitive files outside the intended volume directory, resulting in a high confidentiality impact with no integrity or availability impact. There is no evidence of impact to subsequent systems, and the vendor confirms no exploitable scenario has been discovered in practice. The practical risk is therefore low, but the theoretical exposure involves unauthorized file disclosure from the server's local filesystem (Github Advisory, GitHub Advisory).

Exploitability

There is no known public proof-of-concept exploit, no evidence of in-the-wild exploitation, and no threat actor attribution associated with this vulnerability. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable. The EPSS score is approximately 0.148%, indicating a very low probability of exploitation within 30 days. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, GitHub Advisory).

Mitigation and workarounds

Craft CMS users should update to version 5.10.6 or later for 5.x installations, or to version 4.18.2 or later for 4.x installations. The vendor recommends the update as a hardening measure even though no directly exploitable scenario has been identified. No specific configuration-based workarounds have been published (GitHub Advisory, Github Advisory).

Community reactions

The Craft CMS security team (via user angrybrad) published the advisory with a "Low" severity rating and explicitly noted the issue is not directly exploitable, framing the fix as a hardening recommendation. No significant independent researcher commentary, media coverage, or notable community discussion has been identified for this vulnerability (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Craft CMS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-72785CRITICAL9.3
  • Craft CMS logoCraft CMS
  • cpe:2.3:a:craftcms:craft_cms
NoYesAug 11, 2026
CVE-2026-72786HIGH7.1
  • Craft CMS logoCraft CMS
  • cpe:2.3:a:craftcms:craft_cms
NoYesAug 12, 2026
CVE-2026-72784MEDIUM6.9
  • Craft CMS logoCraft CMS
  • cpe:2.3:a:craftcms:craft_cms
NoYesAug 11, 2026
CVE-2026-72783MEDIUM6.9
  • Craft CMS logoCraft CMS
  • cpe:2.3:a:craftcms:craft_cms
NoYesAug 11, 2026
CVE-2026-72787MEDIUM5.1
  • Craft CMS logoCraft CMS
  • cpe:2.3:a:craftcms:craft_cms
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management