CVE-2026-65693

Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in TwigView::render(), which lacks SandboxExtension or a SecurityPolicy, to inject malicious expressions such as filter('system') into mail template bodies stored unsanitized in the database, causing automatic payload execution on each subsequent application event that triggers a mail dispatch.
Configurations

No configuration.

History

24 Jul 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-24 16:16

Updated : 2026-07-28 20:37


NVD link : CVE-2026-65693

Mitre link : CVE-2026-65693

CVE.ORG link : CVE-2026-65693


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')