CVE-2026-25526Disclosure(hubspot / jinjava)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch hubspot jinjava systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-in sandbox restrictions. This issue has been patched in versions 2.7.6 and 2.8.3.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jinjava

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 15 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 12 signals
  • Disclosure: 9 classified signals
  • General: 3 classified signals
  • Peaked 6d ago at 3 mentions (2026-02-05); latest day: 1
  • 15 total mentions across 9 days

Affected systems

Vendors
Products
jinjava

Deep dive

Activity timeline15 mentions / 9d
01223Mentions · 2026-02-03: 1Mentions · 2026-02-04: 2Mentions · 2026-02-05: 3Mentions · 2026-02-09: 2Mentions · 2026-02-10: 3Mentions · 2026-02-13: 1Mentions · 2026-02-14: 1Mentions · 2026-03-16: 1Mentions · 2026-03-22: 1PoC Mentioned / Linked · 2026-02-13: 1PoC Mentioned / Linked · 2026-02-14: 1Patch / Workaround · 2026-02-05: 2Patch / Workaround · 2026-02-10: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-04: 1Technical Details · 2026-02-05: 3Technical Details · 2026-02-09: 2Technical Details · 2026-02-10: 2Technical Details · 2026-02-14: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-22: 102-0302-0402-0502-0902-1002-1302-1403-1603-22
Signal classification3 categories
Disclosure
960.0%
General
320.0%
Patch
320.0%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-02-031
Disclosure1
2026-02-042
Disclosure2
2026-02-053
General1Patch2
2026-02-092
Disclosure2
2026-02-103
Disclosure1General1Patch1
2026-02-131
General1
2026-02-141
Disclosure1
2026-03-161
Disclosure1
2026-03-221
Disclosure1
Full discourse15 posts
  • Avanthika Anand@av4nth1ka
    General

    New blog post: Reversing CVE-2026-25526 — From Patch Diff to File Read 🔗 : https://av4nth1ka.github.io/jinjava-rce-cve-2026-25526/ #CVE #Security #sandbox

    Post summary

    The post announces a blog post about CVE‑2026‑25526 and links to it, but provides no explicit exploit code, patch information, or active exploitation evidence.

    00071198
    248 followersView on X
  • White Rabbitx@TheRabbitPy
    Disclosure

    🚨 CVE-2026-25526 (CVSS 9.8): HubSpot Jinjava sandbox bypass → arbitrary Java class instantiation/file read via ForTag/ObjectMapper. Template engines alert! https://feedly.com/cve/severity/9-10?page=5

    Post summary

    The tweet alerts to a high‑severity (CVSS 9.8) sandbox bypass in HubSpot’s Jinjava engine that enables arbitrary Java class instantiation and file read, but it does not provide a PoC, exploit code, patch, or evidence of current exploitation.

    0102059
    374 followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    CVE-2026-25526: ثغرة خطيرة في Jinjava تم اكتشاف ثغرة حرجة في Jinjava، محرك القوالب الشائع، تحمل الرقم CVE-2026-25526. تسمح هذه الثغرة للمهاجم بتنفيذ أوامر عن بعد على الأنظمة المتأثرة. الخطر كبير نظرًا لاستخدام Jinjava في عدد كبير من المواقع على HubSpot CMS. 💡 الحماية: - التأكد من تحديث Jinjava إلى آخر إصدار متوفر. - مراجعة سجلات الأمان بحثًا عن أي نشاط مشبوه. - تطبيق مبدأ أقل امتياز للحد من الأضرار المحتملة. 🔗 https://securityonline.info/cve-2026-25526-critical-jinjava-flaw-cvss-9-8-permits-remote-code-execution/ #الأمن_السيبراني #ثغرات #Jinjava

    Post summary

    The text reports a critical remote code execution vulnerability (CVE‑2026‑25526) in Jinjava with a CVSS of 9.8 and urges users to update to the latest version and monitor logs, with no evidence of active exploitation or PoC.

    0003062
    51 followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-25526: 重大な Jinjava の脆弱性 (CVSS 9.8) によりリモートコード実行が可能 CVE-2026-25526: Critical Jinjava Flaw (CVSS 9.8) Permits Remote Code Execution #DailyCyberSecurity (Feb 9) https://securityonline.info/cve-2026-25526-critical-jinjava-flaw-cvss-9-8-permits-remote-code-execution/

    Post summary

    The article announces a critical remote code execution flaw in Jinjava (CVE-2026-25526) with a CVSS score of 9.8, without providing proof‑of‑concept details or mitigation information.

    00030274
    4.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-32711 2 - CVE-2026-1731 3 - CVE-2025-61732 4 - CVE-2026-20817 5 - CVE-2026-25526 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists the top five trending CVEs without offering any technical details, exploit information, or remediation advice.

    00010220
    1.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25526 JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable t… https://www.cve.org/CVERecord?id=CVE-2026-25526

    Post summary

    The entry announces a vulnerability in JinJava prior to versions 2.7.6 and 2.8.3 and links to the CVE record, but provides no detailed technical or exploit information.

    00010197
    56.5K followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #CVE202625526 CVE-2026-25526: Critical Jinjava Flaw (CVSS 9.8) Permits Remote Code Execution https://securityonline.info/cve-2026-25526-critical-jinjava-flaw-cvss-9-8-permits-remote-code-execution/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces a newly disclosed CVE‑2026‑25526 affecting Jinjava with a critical CVSS score and RCE impact, without providing PoC, exploit code, or patch details.

    0000082
    1.5K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 Reversing #CVE-2026-25526: How a Patch Diff in HubSpot’s Jinjava Led to Pre-Auth File Read + Video https://undercodetesting.com/reversing-cve-2026-25526-how-a-patch-diff-in-hubspots-jinjava-led-to-pre-auth-file-read-video/ Educational Purposes!

    Post summary

    The post describes an educational reversal of CVE‑2026‑25526, detailing a pre‑auth file‑read flaw uncovered through a patch diff, and provides a link to a video demonstration.

    0000037
    391 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    CVE-2026-25526: Critical Jinjava Flaw (CVSS 9.8) Permits Remote Code Execution https://securityonline.info/cve-2026-25526-critical-jinjava-flaw-cvss-9-8-permits-remote-code-execution/

    Post summary

    A new critical CVE (CVE‑2026‑25526) in Jinjava is disclosed, rated CVSS 9.8 and allowing remote code execution.

    0000062
    299 followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    CVE-2026-25526: Critical Jinjava Flaw (CVSS 9.8) Permits Remote Code Execution https://securityonline.info/cve-2026-25526-critical-jinjava-flaw-cvss-9-8-permits-remote-code-execution/

    Post summary

    The text announces a critical remote‑code‑execution flaw in Jinjava (CVE‑2026‑25526) with a CVSS score of 9.8, without providing PoC, exploit, or patch details.

    0000060
    73 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    JinJava users, a critical arbitrary Java execution flaw (CVE-2026-25526) has been identified. This bypass through ForTag requires attention. Update to the patched version. #JinJava #Java #infosec https://www.pulsepatch.io/posts/cve-2026-25526-jinjava-arbitrary-java-execution

    Post summary

    A critical arbitrary Java execution vulnerability (CVE-2026-25526) has been identified in JinJava with a ForTag bypass, and users are urged to apply the patched version immediately.

    0000047
    1 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25526: CRITICAL] JinJava template engine had a cyber security vulnerability allowing arbitrary Java execution. The issue is fixed in versions 2.7.6 and 2.8.3, addressing the Java class instantiatio...#cve,CVE-2026-25526,#cybersecurity https://cvefind.com/CVE-2026-25526

    Post summary

    CVE-2026-25526 is a critical vulnerability in JinJava that permits arbitrary Java execution; it has been patched in versions 2.7.6 and 2.8.3.

    0000093
    583 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25526 Arbitrary Java Execution Vulnerability in JinJava Template Engine Before 2.7.6 and 2.8.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25526

    Post summary

    The post references CVE-2026-25526, describing an arbitrary Java execution flaw in JinJava Template Engine versions prior to 2.7.6 and 2.8.3, but provides no PoC, exploit code, active exploitation details, or patch information.

    0000082
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25526: JinJava Bypass through ForTag le... ForTag bypass in JinJava shatters sandbox isolation, enabling trivial arbitrary Java execution and file access with net... https://zerodaysignal.com/vulnerability/CVE-2026-25526 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces the discovery of CVE-2026-25526, a ForTag bypass in JinJava that breaks sandbox isolation to allow arbitrary Java execution and file access.

    0000076
    132 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Jinjava, Sandbox Bypass / Remote Code Execution, #CVE-2026-25526 (Critical) https://dailycve.com/jinjava-sandbox-bypass-remote-code-execution-cve-2026-25526-critical/

    Post summary

    Announcement of a critical CVE in Jinjava allowing sandbox bypass and remote code execution, without mention of exploit code or patches.

    00000181
    162 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphubspotjinjava---

Explore more