Twig Sandbox Security Bypass in October CMS by October
CVE-2026-46696

3.3LOW

Key Information:

Vendor

Octobercms

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-46696?

The October Content Management System features a vulnerability in its Twig sandbox security policy that permits a chained bypass when 'cms.safe_mode' is enabled. This issue arises from the exposure of the Laravel session store to Twig, granting unrestricted method access. Users with CMS markup editing permissions can potentially execute raw SQL expressions, leading to unauthorized access to database values and the ability to manipulate backend session keys. This vulnerability primarily impacts setups intentionally utilizing Safe Mode for demos or multi-tenant environments with untrusted users. Standard production practices discourage enabling Safe Mode, as long as backend access is restricted to trusted admins. To mitigate this issue, all sites utilizing 'cms.safe_mode' should upgrade to patched versions 3.7.17 or 4.2.21. Administrators should also convert CMS markup editing permissions exclusively to trusted users, per standard security guidance.

Affected Version(s)

system < 3.7.17 < 3.7.17

system >= 4.0.0, < 4.2.23 < 4.0.0, 4.2.23

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.