Improper Neutralization of Special Elements Used in a Template Engine in Powermail - CVE-2026-77136
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper neutralization of special elements used in a template engine. A remote user can submit Fluid template syntax to execute arbitrary Fluid ViewHelpers and disclose the server configuration, leading to arbitrary code execution.