Server-Side Template Injection Vulnerability in Microweber CMS
CVE-2026-65693
Key Information:
- Vendor
Microweber
- Status
- Vendor
- CVE Published:
- 24 July 2026
Badges
What is CVE-2026-65693?
Microweber CMS up to version 2.0.20 contains a vulnerability allowing authenticated administrators to execute arbitrary operating system commands. This occurs through the injection of Twig expressions into unsanitized mail templates. Due to the absence of necessary security mechanisms like SandboxExtension or a SecurityPolicy, attackers can exploit this flaw to run malicious code via crafted mail dispatch events. Successful exploitation can lead to severe compromise of system integrity, enabling unauthorized actions by leveraging the unsandboxed Twig rendering environment.
Affected Version(s)
microweber 0 <= 2.0.20
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
