CVE-2026-62996General

LOWCVSS 6.9 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream wrappers and filter chains can be referenced from a template, allowing a php://filter-wrapped resource name to be used to read the contents of arbitrary local files accessible to the PHP process. An attacker able to author or influence a template's resource reference could exploit this to disclose sensitive file contents outside the intended template/config scope. This issue is fixed in version 5.8.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-07: 308-07
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-62996 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-62996

    Post summary

    The post references CVE-2026-62996 for Smarty and links to a database entry but offers no additional details, exploitation evidence, or mitigation information.

    00001149
    4.1K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-62996 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-… https://www.cve.org/CVERecord?id=CVE-2026-62996

    Post summary

    The text merely notes the existence of CVE-2026-62996 for Smarty 5.0.0‑5.8.4 and links to the CVE record, offering no further technical, exploit, or patch details.

    010001.9K
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-62996 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-… https://www.cve.org/CVERecord?id=CVE-2026-62996 ----- Traducción: CVE-2026-62996 Sma… http://infoflow.cloud`

    Post summary

    The tweet simply announces CVE‑2026‑62996 for the Smarty templating engine, linking to the official CVE page, but provides no PoC, exploit, patch, or detailed technical specifics.

    0000034
    98 followersView on X

Explore more