Improper access control in October CMS - #VU149491
Published: September 14, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Twig sandbox SecurityPolicy request-object allowlist when processing Safe Mode Twig templates. A remote privileged user can invoke exposed request-object methods to disclose sensitive information.
Exploitation requires CMS markup editing access.