6.6
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Description
October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox security policy that allowed database write operations when cms.safe_mode is enabled. Backend users with Developer permissions could use Twig template markup to execute insert, update, and delete operations on any database table through the query builder, which is included in the sandbox allow-list. This vulnerability is fixed in 3.7.14 and 4.1.10.
Basic Information
ID
CVE-2026-26274
Source
GitHub_M
Published
Apr 21, 2026 at 16:16
Affected Product
Vendor
octobercms
Product
october
Version
>= 4.0.0, < 4.1.10
Affected Versions
octobercms october >= 4.0.0, < 4.1.10
octobercms october < 3.7.14
octobercms october < 3.7.14