CVE-2026-22692: October CMS: Twig Sandbox Bypass via Collection Methods

Published Apr 14, 2026
·
Updated

A sandbox bypass vulnerability was identified in the optional Twig safe mode feature (CMSSAFEMODE). Certain methods on the collect() helper were not properly restricted, allowing authenticated users with template editing permissions to bypass sandbox protections.

Impact - Bypass of Twig sandbox restrictions - Only affects installations with CMSSAFEMODE enabled (disabled by default) - Requires authenticated backend access with CMS template editing permissions

Patches The vulnerability has been patched in v4.1.5 and v3.7.13. All users who have enabled safe mode are encouraged to upgrade to the latest patched version.

Workarounds If upgrading immediately is not possible: - Disable CMSSAFEMODE if untrusted template editing is not required - Restrict CMS template editing permissions to fully trusted administrators only

References - Reported by Łukasz Rybak

Other sources

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twig safe mode feature (CMSSAFEMODE). Certain methods on the collect() helper were not properly restricted, allowing authenticated users with template editing permissions to bypass sandbox protections. Exploitation requires authenticated backend access with CMS template editing permissions and only affects installations with CMSSAFEMODE enabled (disabled by default). This issue has been fixed in versions 3.7.13 and 4.1.5. To workaround this issue, users can disable CMSSAFEMODE if untrusted template editing is not required, and restrict CMS template editing permissions to fully trusted administrators only.

MITRE

Affected Software

5 affected componentsFixes available
October CMS October CMS<3.7.13, >=4.0.0<=4.1.4
composer/october/rain<=3.7.12
3.7.13
composer/october/rain>=4.0.0<=4.1.4
4.1.5
Octobercms October<3.7.13
Octobercms October>=4.0.0<4.1.5

Event History

Apr 14, 2026
CVE Published
via MITRE·04:48 PM
Data Sourced
via MITRE·04:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
Affected Software
Advisory Published
via GitHub·08:02 PM
Data Sourced
via GitHub·08:02 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-22692?

CVE-2026-22692 has been classified as a high severity vulnerability due to its ability to bypass the Twig sandbox in October CMS.

2

How do I fix CVE-2026-22692?

To mitigate CVE-2026-22692, upgrade to October CMS version 3.7.13 or versions 4.1.5 and above.

3

What systems are affected by CVE-2026-22692?

CVE-2026-22692 affects October CMS versions prior to 3.7.13 and versions 4.0.0 to 4.1.4.

4

What types of attacks can CVE-2026-22692 facilitate?

CVE-2026-22692 can facilitate remote code execution and unauthorized access by bypassing Twig's sandbox restrictions.

5

Is it safe to use October CMS versions prior to 3.7.13 or 4.1.4 with CVE-2026-22692 present?

No, using October CMS versions prior to those mentioned is unsafe as they are vulnerable to CVE-2026-22692.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203