CVE-2026-54390

CRITICAL

JTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-54390. PoCs published by shinthink.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-54390, a critical pre-authentication Server-Side Template Injection (SSTI) in JTL Shop 5.2.0–5.7.1. The exploit leverages Smarty template injection via contact form fields (email subject) to achieve unauthenticated remote code execution (RCE) using `file_get_contents` and other Smarty modifiers.

Description

JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. Attackers can exploit this flaw to read sensitive server-side values such as database credentials and encryption keys, and on versions 5.4.0 through 5.7.1, leverage registered Smarty modifiers including unserialize and file_get_contents to write a webshell to the web root and execute arbitrary commands as the web server user.

Exploits (1)

github WORKING POC
by shinthink · pythonpoc
https://github.com/shinthink/CVE-2026-54390

This repository contains a functional exploit for CVE-2026-54390, a critical pre-authentication Server-Side Template Injection (SSTI) in JTL Shop 5.2.0–5.7.1. The exploit leverages Smarty template injection via contact form fields (email subject) to achieve unauthenticated remote code execution (RCE) using `file_get_contents` and other Smarty modifiers.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: JTL Shop versions 5.2.0 to 5.7.1
No auth needed
Prerequisites: Target must have a contact form enabled · Smarty modifiers like `file_get_contents` must be registered (default in vulnerable versions)
mistral-large-3 · analyzed Jul 10, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0060
EPSS Percentile 45.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1336
Status published
Products (7)
JTL Software/JTL Shop 5.0.0 - 5.1.8
JTL Software/JTL Shop 5.2.0 - 5.3.x
JTL Software/JTL Shop 5.2.0 - 5.4.0
JTL Software/JTL Shop 5.4.0 - 5.7.1
JTL Software/JTL Shop 5.5.4
JTL Software/JTL Shop 5.6.2
JTL Software/JTL Shop 5.7.2
Published Jun 18, 2026
Tracked Since Jun 18, 2026