Back to CVE List

CVE-2026-26067

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
4.9 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Vulnerability Description

October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information disclosure vulnerability was identified in the handling of CSS preprocessor files. Backend users with Editor permissions could craft .less, .sass, or .scss files that leverage the compiler's import functionality to read arbitrary files from the server. This worked even with cms.safe_mode enabled. This vulnerability is fixed in 3.7.14 and 4.1.10.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-184
Source
NVD
Vendor
octobercms
Product
october

External References

Discussion (0)

Add Comment

No comments yet. Be the first!