CVE-2026-22692: October CMS: Twig Sandbox Bypass via Collection Methods
A sandbox bypass vulnerability was identified in the optional Twig safe mode feature (CMSSAFEMODE). Certain methods on the collect() helper were not properly restricted, allowing authenticated users with template editing permissions to bypass sandbox protections.
Impact - Bypass of Twig sandbox restrictions - Only affects installations with CMSSAFEMODE enabled (disabled by default) - Requires authenticated backend access with CMS template editing permissions
Patches The vulnerability has been patched in v4.1.5 and v3.7.13. All users who have enabled safe mode are encouraged to upgrade to the latest patched version.
Workarounds If upgrading immediately is not possible: - Disable CMSSAFEMODE if untrusted template editing is not required - Restrict CMS template editing permissions to fully trusted administrators only
References - Reported by Łukasz Rybak
Other sources
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twig safe mode feature (CMSSAFEMODE). Certain methods on the collect() helper were not properly restricted, allowing authenticated users with template editing permissions to bypass sandbox protections. Exploitation requires authenticated backend access with CMS template editing permissions and only affects installations with CMSSAFEMODE enabled (disabled by default). This issue has been fixed in versions 3.7.13 and 4.1.5. To workaround this issue, users can disable CMSSAFEMODE if untrusted template editing is not required, and restrict CMS template editing permissions to fully trusted administrators only.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22692?
CVE-2026-22692 has been classified as a high severity vulnerability due to its ability to bypass the Twig sandbox in October CMS.
How do I fix CVE-2026-22692?
To mitigate CVE-2026-22692, upgrade to October CMS version 3.7.13 or versions 4.1.5 and above.
What systems are affected by CVE-2026-22692?
CVE-2026-22692 affects October CMS versions prior to 3.7.13 and versions 4.0.0 to 4.1.4.
What types of attacks can CVE-2026-22692 facilitate?
CVE-2026-22692 can facilitate remote code execution and unauthorized access by bypassing Twig's sandbox restrictions.
Is it safe to use October CMS versions prior to 3.7.13 or 4.1.4 with CVE-2026-22692 present?
No, using October CMS versions prior to those mentioned is unsafe as they are vulnerable to CVE-2026-22692.