CVE-2026-26067

October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information disclosure vulnerability was identified in the handling of CSS preprocessor files. Backend users with Editor permissions could craft .less, .sass, or .scss files that leverage the compiler's import functionality to read arbitrary files from the server. This worked even with cms.safe_mode enabled. This vulnerability is fixed in 3.7.14 and 4.1.10.
Configurations

No configuration.

History

21 Apr 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-21 17:16

Updated : 2026-04-22 21:08


NVD link : CVE-2026-26067

Mitre link : CVE-2026-26067

CVE.ORG link : CVE-2026-26067


JSON object : View

Products Affected

No product.

CWE
CWE-184

Incomplete List of Disallowed Inputs

CWE-863

Incorrect Authorization