9.9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.
AI Analysis
Server-Side Template Injection (SSTI) vulnerability in Mautic's theme engine, allowing authenticated users to execute arbitrary code or access restricted system files
Basic Information
ID
CVE-2026-9558
Source
Mautic
Published
May 29, 2026 at 10:01
Modified
May 29, 2026 at 10:49
Affected Product
Vendor
Mautic
Product
Mautic
Version
7.0.0
Affected Versions
1.3.0
5.0.0
6.0.0
7.0.0
5.0.0
6.0.0
7.0.0
CWE Classification
AI Assessment
AI Score
9.9 / 10
AI Severity
Critical
Vendor
Mautic
Product
Mautic
Version
1.3.0, 5.0.0, 6.0.0, 7.0.0