← volver
CVE-2026-69118highCWE-1336CWE-863

Cachet 2.4.1 Authenticated Server-Side Template Injection RCE

41Vexday Risk Score

Sin señal de explotación. Ella tiene prueba de concepto pública.

ssvc Attendcvss 8.7epss 0.6%
probabilidad de explotación
0.6%top 57% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade directives or Twig filters that execute system commands when incidents are created, achieving remote code execution as the web server process.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
cachethq · cachet
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.