Code Injection Vulnerability in Smarty by Smarty
CVE-2026-82531

9.2CRITICAL

Key Information:

Vendor

Smarty-PHP

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-82531?

Smarty prior to version 4.5.8 and 5.x before 5.8.5 has a code injection vulnerability that arises due to improper handling of the nocache_hash during template inheritance. This oversight allows attackers to introduce malicious code through crafted assigned data containing a forged SmartyNocache marker. When the PHP cache file is regenerated, this marker is executed without validation, leading to potential remote code execution risks. Users of affected Smarty versions are encouraged to update to the latest releases to mitigate this vulnerability.

Affected Version(s)

smarty 0 < 4.5.8

smarty 5.0.0 < 5.8.5

smarty 4.5.8

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MegaManSec
.