CVE-2026-65693

HIGH

Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates

Title source: cna
STIX 2.1

Description

Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in TwigView::render(), which lacks SandboxExtension or a SecurityPolicy, to inject malicious expressions such as filter('system') into mail template bodies stored unsanitized in the database, causing automatic payload execution on each subsequent application event that triggers a mail dispatch.

References (2)

Core 2
Core References
Exploit technical-description exploit
Researcher Disclosure
https://gist.github.com/W40X/584f4b088d310bc5280cc74bbf97831a

Scores

CVSS v3 7.2
EPSS 0.0048
EPSS Percentile 38.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
microweber/microweber < 2.0.20
Published Jul 24, 2026
Tracked Since Jul 24, 2026