Back to CVE List

CVE-2026-26274

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.6 / 10
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox security policy that allowed database write operations when cms.safe_mode is enabled. Backend users with Developer permissions could use Twig template markup to execute insert, update, and delete operations on any database table through the query builder, which is included in the sandbox allow-list. This vulnerability is fixed in 3.7.14 and 4.1.10.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-184
Source
NVD
Vendor
octobercms
Product
october

External References

Discussion (0)

Add Comment

No comments yet. Be the first!