CVE-2026-8740: Sanluan PublicCMS templateResult API TemplateResultDirective.java execute special elements used in a template engine

Published May 17, 2026
·
Updated

A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccms-core/src/main/java/com/publiccms/views/directive/tools/TemplateResultDirective.java of the component templateResult API. This manipulation of the argument templateContent causes improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

1 affected component
Sanluan PublicCMS=5.202506.d

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Sanluan PublicCMS templateResult API from your environment.

    Remove or uninstall the templateResult API / TemplateResultDirective class from deployments if it is not required by the application to eliminate the vulnerable functionality.

  2. Configuration

    Disable the templateResult API or the TemplateResultDirective implementation to prevent processing of untrusted templateContent that could lead to remote template-engine injection.

    Sanluan PublicCMS templateResult API (TemplateResultDirective) enabled = false
  3. Compensating control

    Restrict access to the templateResult API to trusted management networks or specific IP addresses at the network perimeter or host firewall. Deploy WAF rules to detect and block malicious template payloads targeting templateContent.

  4. Operational

    Monitor webserver and application logs for attempts targeting templateResult or TemplateResultDirective, scan for indicators of compromise, and rotate credentials if a compromise is suspected. Apply any vendor-supplied fixes or updates when they become available.

Event History

May 17, 2026
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Jun 29, 58424
Event
via FIRST·11:03 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-8740?

CVE-2026-8740 has been classified with a high severity due to potential exploitation allowing unauthorized access.

2

How do I fix CVE-2026-8740?

To mitigate CVE-2026-8740, it is recommended to upgrade Sanluan PublicCMS to the latest version that addresses this vulnerability.

3

What versions of Sanluan PublicCMS are affected by CVE-2026-8740?

CVE-2026-8740 affects Sanluan PublicCMS version 5.202506.d specifically.

4

What type of vulnerability is CVE-2026-8740?

CVE-2026-8740 is an API flaw found in the template engine of Sanluan PublicCMS.

5

Can CVE-2026-8740 lead to data breaches?

Yes, if exploited, CVE-2026-8740 could potentially lead to unauthorized access and data breaches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203