CVE-2026-65693
HIGHMicroweber CMS 2.0.20 Server-Side Template Injection via Mail Templates
Title source: cnaDescription
Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in TwigView::render(), which lacks SandboxExtension or a SecurityPolicy, to inject malicious expressions such as filter('system') into mail template bodies stored unsanitized in the database, causing automatic payload execution on each subsequent application event that triggers a mail dispatch.
References (2)
Core 2
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://gist.github.com/W40X/584f4b088d310bc5280cc74bbf97831a
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/microweber-cms-server-side-template-injection-via-mail-templates
Scores
CVSS v3
7.2
EPSS
0.0048
EPSS Percentile
38.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (1)
microweber/microweber
< 2.0.20
Published
Jul 24, 2026
Tracked Since
Jul 24, 2026