CVE-2026-69118: Cachet 2.4.1 Authenticated Server-Side Template Injection RCE
Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade directives or Twig filters that execute system commands when incidents are created, achieving remote code execution as the web server process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-69118?
The severity of CVE-2026-69118 is high with a score of 8.8.
How do I fix CVE-2026-69118?
To fix CVE-2026-69118, upgrade to a later version of Cachet that addresses this vulnerability.
What type of vulnerability is CVE-2026-69118?
CVE-2026-69118 is an authenticated server-side template injection vulnerability.
Who is affected by CVE-2026-69118?
Authenticated users of Cachet version 2.4.1 are affected by CVE-2026-69118.
What can attackers do with CVE-2026-69118?
Attackers can exploit CVE-2026-69118 to execute arbitrary PHP code on the server.