CVE-2026-79774

Source
https://cve.org/CVERecord?id=CVE-2026-79774
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79774.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-79774
Aliases
Published
2026-08-25T15:16:05.738Z
Modified
2026-08-28T11:30:21.248628375Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
Winter CMS before 1.2.13 Twig Sandbox Escape via SecurityPolicy
Details

Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\Twig\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers can exploit method forwarding through Eloquent models and query builders using methods like saveQuietly(), deleteQuietly(), increment(), decrement(), and newQuery() to read and modify arbitrary database records, execute arbitrary SQL, and achieve remote code execution by injecting PHP into template code sections.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-693"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79774.json"
}
References

Affected packages

Git / github.com/wintercms/winter

Affected ranges

Type
GIT
Repo
https://github.com/wintercms/winter
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.2.7"
        },
        {
            "fixed": "1.2.13"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79774.json"