CVE-2026-8740: Sanluan PublicCMS templateResult API TemplateResultDirective.java execute special elements used in a template engine
A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccms-core/src/main/java/com/publiccms/views/directive/tools/TemplateResultDirective.java of the component templateResult API. This manipulation of the argument templateContent causes improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sanluan PublicCMS templateResult APIfrom your environment.Remove or uninstall the templateResult API / TemplateResultDirective class from deployments if it is not required by the application to eliminate the vulnerable functionality.
- Configuration
Disable the templateResult API or the TemplateResultDirective implementation to prevent processing of untrusted templateContent that could lead to remote template-engine injection.
Sanluan PublicCMS templateResult API (TemplateResultDirective) enabled = false - Compensating control
Restrict access to the templateResult API to trusted management networks or specific IP addresses at the network perimeter or host firewall. Deploy WAF rules to detect and block malicious template payloads targeting templateContent.
- Operational
Monitor webserver and application logs for attempts targeting templateResult or TemplateResultDirective, scan for indicators of compromise, and rotate credentials if a compromise is suspected. Apply any vendor-supplied fixes or updates when they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8740?
CVE-2026-8740 has been classified with a high severity due to potential exploitation allowing unauthorized access.
How do I fix CVE-2026-8740?
To mitigate CVE-2026-8740, it is recommended to upgrade Sanluan PublicCMS to the latest version that addresses this vulnerability.
What versions of Sanluan PublicCMS are affected by CVE-2026-8740?
CVE-2026-8740 affects Sanluan PublicCMS version 5.202506.d specifically.
What type of vulnerability is CVE-2026-8740?
CVE-2026-8740 is an API flaw found in the template engine of Sanluan PublicCMS.
Can CVE-2026-8740 lead to data breaches?
Yes, if exploited, CVE-2026-8740 could potentially lead to unauthorized access and data breaches.