CVE-2021-27903
About
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).
Rainforest analyst review
The headline here is "Remote Code Execution," but read the description twice: it only triggers on sites that left administrative changes unrestricted, and only if an attacker has already hijacked an admin's session. In other words, this is a post-compromise escalation of an existing admin foothold into code execution on the server, not a way in from the outside. The damage if it fires is real, but the entry ticket is already the keys to the kingdom.
That gate matters enormously for how we rank it. Craft CMS ships with a hardened production default that disables admin changes precisely to close this off, so a well-configured site is not exposed at all. The realistic path to abuse is session hijacking plus a lax config plus an admin actually being targeted, which is a chain of preconditions, not a mass-exploitation scenario. Nobody is spraying the internet for this the way they would for an unauthenticated bug, despite the 9.8 label.
Our angle is to treat the CVSS score as misleading and rank by config state instead. The question we ask isn't "which Craft installs exist" but "which ones run with allowAdminChanges enabled in production and are below 3.6.7" — that intersection is the small set that genuinely matters. For everything on the hardened default, this drops well down the queue behind bugs that don't require an attacker to already own an admin session.
References
Related CVEs
Frequently asked questions
What is CVE-2021-27903?
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).
How severe is CVE-2021-27903?
CVE-2021-27903 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2021-27903 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2021-27903?
Public advisories list the following as affected: craft cms. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2021-27903?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
