CVE-2026-76802: Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass

Published Sep 22, 2026
·
Updated

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzzing: block and an unsigned code: block. When an operator enables -dast, an untrusted multiprotocol template can place an unsigned code request into the execution queue and run arbitrary shell commands even without -code or a valid cryptographic signature. The issue affects CLI DAST scans and SDK integrations that enable DAST while accepting attacker-supplied templates. This issue is fixed in version 3.10.0.

Affected Software

1 affected component
ProjectDiscovery nuclei>=3.0.0<3.10.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Nuclei to a version that resolves this vulnerability.

    Fixed in 3.10.0

Event History

Sep 22, 2026
CVE Published
via MITRE·04:47 PM
Data Sourced
via MITRE·04:47 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

CLI DAST scans and SDK integrations are affected when they enable DAST and accept attacker-supplied multiprotocol templates. The vulnerable path requires the operator to use the -dast option.

2

What must an attacker provide to execute commands?

An attacker needs to supply an untrusted multiprotocol template containing both a fuzzing: block and an unsigned code: block. The template can then queue an unsigned code request and execute arbitrary shell commands without -code or a valid cryptographic signature.

3

Are installations that do not enable DAST affected by this bypass?

The described vulnerable branch is the DAST template-loading path, and exploitation requires -dast to be enabled. The provided information does not identify non-DAST scans as affected.

4

What version fixes the issue?

Version 3.10.0 fixes the issue. Versions from 3.0.0 until 3.10.0 are identified as affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203