CVE-2026-1770

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass sandbox restrictions and obtain RCE (Remote Code Execution).
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-02-02 17:16

Updated : 2026-02-03 16:44


NVD link : CVE-2026-1770

Mitre link : CVE-2026-1770

CVE.ORG link : CVE-2026-1770


JSON object : View

Products Affected

No product.

CWE
CWE-913

Improper Control of Dynamically-Managed Code Resources