CVE-2026-9558
Summary
| CVE | CVE-2026-9558 |
|---|---|
| State | PUBLISHED |
| Assigner | Mautic |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-29 11:16:17 UTC |
| Updated | 2026-05-29 15:39:34 UTC |
| Description | A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. |
Risk And Classification
Primary CVSS: v3.1 9.9 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Problem Types: CWE-1336 | CWE-1336 CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.9 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.9 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
There are no known software configurations currently associated with this CVE in NVD or the CVE Program record.
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/mautic/mautic/security/advisories/GHSA-9fx4-7cmj-47vg | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Onurcan Genç (@onurcangnc) (en)
CNA: Daniel Zhang (@xfer0) (en)
CNA: Tuan Do (@Entropt) (en)
CNA: Patryk Gruszka (@patrykgruszka) (en)
CNA: John Linhart (@escopecz) (en)
CNA: Leuchtfeuer Digital Marketing (@Leuchtfeuer) (en)
Additional Advisory Data
Workarounds
CNA: There are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions (core:themes:create) to only highly trusted administrators.
There are currently no legacy QID mappings associated with this CVE.