CVE-2026-26274Disclosure

LOWCVSS 6.6 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox security policy that allowed database write operations when cms.safe_mode is enabled. Backend users with Developer permissions could use Twig template markup to execute insert, update, and delete operations on any database table through the query builder, which is included in the sandbox allow-list. This vulnerability is fixed in 3.7.14 and 4.1.10.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-21: 2Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-21: 204-21
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26274 October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox security policy that all… https://www.cve.org/CVERecord?id=CVE-2026-26274 ----- Traducción: CVE-2026-26274 Oct… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-26274, noting the vulnerability in the Twig sandbox policy before specific CMS/website platform versions, and hints at a patch through reference to newer versions.

    0001023
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-26274 October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox security policy that all… https://www.cve.org/CVERecord?id=CVE-2026-26274

    Post summary

    The text references CVE-2026-26274, noting a Twig sandbox policy flaw in older October CMS releases, but offers no PoC, exploit code, evidence of active exploitation, or patch information.

    00000139
    57.2K followersView on X

Explore more