PHP Framework Vulnerability in Phalcon 5.15.0 and Earlier
CVE-2026-59989

9.2CRITICAL

Key Information:

Vendor

Phalcon

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-59989?

In the Phalcon framework, a vulnerability exists in the resolveFilter method of the Volt compiler, where raw separator and array token values are directly inserted into generated PHP code without proper sanitization. This flaw allows attackers with influence over Volt templates to craft malicious input that can break quotes, leading to arbitrary PHP code execution in the compiled cache once the template is rendered. The issue has been addressed in version 5.16.0, and users of affected versions are advised to update promptly to mitigate risks.

Affected Version(s)

cphalcon < 5.16.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.