Search/CVE-2026-1770
CVE

CVE-2026-1770

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass sandbox restrictions and obtain RCE (Remote Code Execution).

CVSS v3.1
EPSS
0.44%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Sep 2, 2026
0.02pp
0.43% → 0.44% over 2 tracked changes
Connections
1 relationships
Timeline
disclosure → media coverage
Feb 2, 2026
Disclosure — published as a CVE record. · last revised by NVD Apr 15, 2026