Improper privilege management in October CMS - CVE-2026-46696

 

Improper privilege management in October CMS - CVE-2026-46696

Published: September 14, 2026


Vulnerability identifier: #VU149493
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-46696
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to read arbitrary database values and impersonate an existing superuser.

The vulnerability exists due to improper access control in the Twig sandbox security policy when processing CMS markup templates with safe mode enabled. A remote privileged user can invoke raw SQL methods through forwarded builder calls and write a forged backend authentication session value to impersonate an existing superuser.

Exploitation requires CMS markup editing access and the presence of an existing superuser account.


Affected software

October CMS

How to mitigate CVE-2026-46696

Install security update from vendor's website.

October CMS - addressed in versions 3.7.17, 4.2.23

External References

Related Security Bulletins