Skip to main content
HIGH

CVE-2026-92592

CVSS v3

8.8

HIGH

EPSS Score

0.6 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound to its purpose (Yii's cookieValidationKey is derived from the same Craft securityKey used for signed request parameters). An authenticated, non-administrator user (Control Panel access is not required) can set the cookie via the license-shun endpoint and trans

Technical details

Published
2026-09-16
Last Modified
2026-09-17

Frequently asked questions

What is CVE-2026-92592?

Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound to its purpose (Yii's cookieValidationKey is derived from the same Craft securityKey used for signed request parameters). An authenticated, non-administrator user (Control Panel access is not required) can set the cookie via the license-shun endpoint and trans

Is CVE-2026-92592 actively exploited?

Active exploitation of CVE-2026-92592 has not been confirmed. Its EPSS score was 0.6% on 2026-09-28, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-92592?

CVE-2026-92592 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2026-92592 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key