CVE-2026-26274
MEDIUMOctober: Safe Mode Bypass via Twig Database Write Operations
Title source: cnaDescription
October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox security policy that allowed database write operations when cms.safe_mode is enabled. Backend users with Developer permissions could use Twig template markup to execute insert, update, and delete operations on any database table through the query builder, which is included in the sandbox allow-list. This vulnerability is fixed in 3.7.14 and 4.1.10.
Scores
CVSS v3
6.6
EPSS
0.0007
EPSS Percentile
21.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-184
CWE-863
Status
published
Products (3)
october/october
0 - 3.7.14Packagist
octobercms/october
< 3.7.14
octobercms/october
>= 4.0.0, < 4.1.10
Published
Apr 21, 2026
Tracked Since
Apr 21, 2026