#VU125892 Improper access control in October CMS - CVE-2026-22692
Published: April 14, 2026
October CMS
OctoberCMS
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Twig safe mode sandbox when invoking certain methods on the collect() helper. A remote privileged user can use unrestricted collection methods to bypass sandbox protections and disclose sensitive information.
Only installations with CMS_SAFE_MODE enabled are vulnerable.