Remote Code Execution Vulnerability in Silverstripe Advanced Workflow Module
CVE-2026-54718
7.2HIGH
What is CVE-2026-54718?
The Silverstripe Advanced Workflow module allows attackers with appropriate permissions to exploit a vulnerability in the handling of email templates. Specifically, prior to updates in versions 6.4.5, 7.1.3, and 7.2.1, an attacker could insert malicious server-side template code in the email template fields. When these fields are processed by the Silverstripe template engine, it could lead to arbitrary code execution on the server. To mitigate this risk, users are advised to update to the patched versions as soon as possible.
Affected Version(s)
silverstripe-advancedworkflow < 6.4.5 < 6.4.5
silverstripe-advancedworkflow >= 7.0.0, < 7.1.3 < 7.0.0, 7.1.3
silverstripe-advancedworkflow >= 7.2.0, < 7.2.1 < 7.2.0, 7.2.1
