Количество 4
Количество 4
CVE-2026-46696
October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. The Laravel session store was exposed to Twig with unrestricted method access, and raw SQL methods reachable through Eloquent's `__call` forwarding were not blocked across the full builder chain. When combined, a backend user with CMS markup editing access could read arbitrary database values via raw SQL expressions and write to the backend authentication session key, forging a backend session as another existing user. The scope of impact is narrow. Safe Mode is a niche feature, primarily used for demo installations and multi-tenant or shared-editor scenarios where untrusted users are deliberately granted access to the CMS markup editor. Standard production deployments do not enable Safe Mode, because under normal October CMS guidance backend access - i
CVE-2026-46696
October System provides the system module for October Content Manageme ...
GHSA-xv9m-fm3w-8w5x
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
BDU:2026-14919
Уязвимость политики безопасности Twig CMS-системы October CMS, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-46696 October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. The Laravel session store was exposed to Twig with unrestricted method access, and raw SQL methods reachable through Eloquent's `__call` forwarding were not blocked across the full builder chain. When combined, a backend user with CMS markup editing access could read arbitrary database values via raw SQL expressions and write to the backend authentication session key, forging a backend session as another existing user. The scope of impact is narrow. Safe Mode is a niche feature, primarily used for demo installations and multi-tenant or shared-editor scenarios where untrusted users are deliberately granted access to the CMS markup editor. Standard production deployments do not enable Safe Mode, because under normal October CMS guidance backend access - i | CVSS3: 3.3 | 0% Низкий | 7 дней назад | |
CVE-2026-46696 October System provides the system module for October Content Manageme ... | CVSS3: 3.3 | 0% Низкий | 7 дней назад | |
GHSA-xv9m-fm3w-8w5x October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls | CVSS3: 3.3 | 0% Низкий | 7 дней назад | |
BDU:2026-14919 Уязвимость политики безопасности Twig CMS-системы October CMS, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 3.3 | 0% Низкий | 9 дней назад |
Уязвимостей на страницу