CVE-2026-9558

CRITICAL

Mautic - Authenticated Server-Side Template Injection via Theme Engine

Title source: llm
STIX 2.1

Description

A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.

Scores

CVSS v3 9.9
EPSS 0.0057
EPSS Percentile 43.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1336
Status published
Products (4)
mautic/core 1.3.0Packagist
mautic/core 5.0.0 - 5.2.11Packagist
mautic/core 6.0.0 - 6.0.9Packagist
mautic/core 7.0.0 - 7.1.2Packagist
Published May 29, 2026
Tracked Since May 29, 2026