Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

nvd логотип

CVE-2026-46696

7 дней назад

October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. The Laravel session store was exposed to Twig with unrestricted method access, and raw SQL methods reachable through Eloquent's `__call` forwarding were not blocked across the full builder chain. When combined, a backend user with CMS markup editing access could read arbitrary database values via raw SQL expressions and write to the backend authentication session key, forging a backend session as another existing user. The scope of impact is narrow. Safe Mode is a niche feature, primarily used for demo installations and multi-tenant or shared-editor scenarios where untrusted users are deliberately granted access to the CMS markup editor. Standard production deployments do not enable Safe Mode, because under normal October CMS guidance backend access - i

CVSS3: 3.3
EPSS: Низкий
debian логотип

CVE-2026-46696

7 дней назад

October System provides the system module for October Content Manageme ...

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xv9m-fm3w-8w5x

7 дней назад

October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls

CVSS3: 3.3
EPSS: Низкий
fstec логотип

BDU:2026-14919

9 дней назад

Уязвимость политики безопасности Twig CMS-системы October CMS, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-46696

October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. The Laravel session store was exposed to Twig with unrestricted method access, and raw SQL methods reachable through Eloquent's `__call` forwarding were not blocked across the full builder chain. When combined, a backend user with CMS markup editing access could read arbitrary database values via raw SQL expressions and write to the backend authentication session key, forging a backend session as another existing user. The scope of impact is narrow. Safe Mode is a niche feature, primarily used for demo installations and multi-tenant or shared-editor scenarios where untrusted users are deliberately granted access to the CMS markup editor. Standard production deployments do not enable Safe Mode, because under normal October CMS guidance backend access - i

CVSS3: 3.3
0%
Низкий
7 дней назад
debian логотип
CVE-2026-46696

October System provides the system module for October Content Manageme ...

CVSS3: 3.3
0%
Низкий
7 дней назад
github логотип
GHSA-xv9m-fm3w-8w5x

October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls

CVSS3: 3.3
0%
Низкий
7 дней назад
fstec логотип
BDU:2026-14919

Уязвимость политики безопасности Twig CMS-системы October CMS, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.3
0%
Низкий
9 дней назад

Уязвимостей на страницу