Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-14919

Опубликовано: 13 сент. 2026
Источник: fstec
CVSS3: 3.3
CVSS2: 3.6
EPSS Низкий

Описание

Уязвимость политики безопасности Twig CMS-системы October CMS связана с небезопасным управлением привилегиями. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, получить несанкционированный доступ к защищаемой информации

Вендор

Сообщество свободного программного обеспечения

Наименование ПО

October CMS

Версия ПО

до 3.7.17 (October CMS)
до 4.2.23 (October CMS)

Тип ПО

Сетевое средство

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Низкий уровень опасности (базовая оценка CVSS 2.0 составляет 3,6)
Низкий уровень опасности (базовая оценка CVSS 3.1 составляет 3,3)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://github.com/octobercms/october/security/advisories/GHSA-xv9m-fm3w-8w5x

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 12%
0.00216
Низкий

3.3 Low

CVSS3

3.6 Low

CVSS2

Связанные уязвимости

CVSS3: 3.3
nvd
7 дней назад

October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. The Laravel session store was exposed to Twig with unrestricted method access, and raw SQL methods reachable through Eloquent's `__call` forwarding were not blocked across the full builder chain. When combined, a backend user with CMS markup editing access could read arbitrary database values via raw SQL expressions and write to the backend authentication session key, forging a backend session as another existing user. The scope of impact is narrow. Safe Mode is a niche feature, primarily used for demo installations and multi-tenant or shared-editor scenarios where untrusted users are deliberately granted access to the CMS markup editor. Standard production deployments do not enable Safe Mode, because under normal October CMS guidance backend access - i

CVSS3: 3.3
debian
7 дней назад

October System provides the system module for October Content Manageme ...

CVSS3: 3.3
github
7 дней назад

October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls

EPSS

Процентиль: 12%
0.00216
Низкий

3.3 Low

CVSS3

3.6 Low

CVSS2