CVE-2026-62992Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before validating that a requested path lies within a configured secure directory. An attacker able to place or reference a symlink within a directory Smarty treats as trusted (e.g., a template or config directory) could use it to point outside the intended secure directory, bypassing the containment check and reading arbitrary files accessible to the PHP process. This issue is fixed in versions 5.8.2 and 4.5.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-61

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-07); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-07: 2Mentions · 2026-08-08: 1Patch / Workaround · 2026-08-08: 1Technical Details · 2026-08-07: 1Technical Details · 2026-08-08: 108-0708-08
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-072
Disclosure1General1
2026-08-081
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-62992 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Securi… https://www.cve.org/CVERecord?id=CVE-2026-62992

    Post summary

    The message provides a brief disclosure of CVE‑2026‑62992, noting the affected Smarty versions but offering no PoC, exploit code, or patch information.

    010101.9K
    57.9K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    🐘 Smarty PHP template engine file-read vulnerability CVE-2026-62992 affects Smarty before 5.8.2, and the affected 4.x branch before 4.5.7. A symlink-handling flaw can bypass trusted-directory containment and potentially expose arbitrary files readable by the PHP process. ✅ Fixed in 5.8.2 and 4.5.7. 🔎 Source: MITRE / VulDB. #PHP #Smarty #CVE #AppSec #CyberSecurity

    Post summary

    The tweet announces a file‑read vulnerability in Smarty (CVE‑2026‑62992), details the technical flaw, and confirms that fixes are available in versions 5.8.2 and 4.5.7.

    0000040
    34 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-62992 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Securi… https://www.cve.org/CVERecord?id=CVE-2026-62992 ----- Traducción: CVE-2026-62992 Sma… http://infoflow.cloud`

    Post summary

    The post briefly mentions CVE-2026-62992 and links to its official record, providing only a version reference without any details on exploitation, mitigation, or verification.

    0000037
    98 followersView on X

Explore more