CVE-2026-79774
Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers can exploit method forwarding through Eloquent models and query builders using methods like saveQuietly(), deleteQuietly(), increment(), decrement(), and newQuery() to read and modify arbitrary database records, execute arbitrary SQL, and achieve remote code execution by injecting PHP into template code sections.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.43%
- CWE
- CWE-693
- Published
- 2026-08-25
- Last modified
- 2026-08-26
Affected products
- wintercms winter
- wintercms winter
Weakness type
Related vulnerabilities
- CVE-2026-0306 — Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows
- CVE-2026-54694 — NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover
- CVE-2026-79638 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-87808 — SiYuan before v3.8.2 Read-Only Boundary Bypass via fullTextSearchBlock
- CVE-2026-78552 — Validation Bypass in Okta Access Gateway Custom Directives
- CVE-2026-81376 — Visual Studio Code Security Feature Bypass Vulnerability
- CVE-2026-77892 — Windows Boot Manager Elevation of Privilege Vulnerability
- CVE-2026-84811 — agentverus-scanner Companion Code Analysis Bypass via Excluded Python Bytecode