CVE-2026-54718: Input Validation
Impact The advanced workflow email template field is vulnerable to a specially crafted payload that can be used to run arbitrary code on the server.
Reported by Steve Boyd Silverstripe Ltd.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/symbiote/silverstripe-advancedworkflowto a version that resolves this vulnerability.Fixed in 7.2.1 - Upgrade
Upgrade
composer/symbiote/silverstripe-advancedworkflowto a version that resolves this vulnerability.Fixed in 7.1.3 - Upgrade
Upgrade
composer/symbiote/silverstripe-advancedworkflowto a version that resolves this vulnerability.Fixed in 6.4.5
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker needs high privileges. The attack can be performed over the network, requires low attack complexity, and does not require user interaction.
What is the potential result of successful exploitation?
A specially crafted payload in the advanced workflow email template field can result in arbitrary code execution on the server. The reported impact includes compromise of confidentiality, integrity, and availability.