Vulnerability Description
Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade directives or Twig filters that execute system commands when incidents are created, achieving remote code execution as the web server process.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/cachethq/cachet/issues/4621
- https://www.vulncheck.com/advisories/cachet-authenticated-server-side-template-i
FAQ
What is CVE-2026-69118?
CVE-2026-69118 is a vulnerability with a CVSS score of 8.8 (HIGH). Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create maliciou...
How severe is CVE-2026-69118?
CVE-2026-69118 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-69118?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.