CVE-2026-74791Disclosure

LOWCVSS 9.2 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without triggering TemplateLoader.Load() again.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-226

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-16); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-16: 2Mentions · 2026-09-09: 1PoC Mentioned / Linked · 2026-09-09: 1Technical Details · 2026-08-16: 2Technical Details · 2026-09-09: 108-1609-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-162
Disclosure2
2026-09-091
Disclosure1
Full discourse3 posts
  • Offensive360@offensive360
    Disclosure

    Scriban's TemplateContext.Reset() clears runtime state but not CachedTemplates. Pool the context across requests and tenant B renders tenant A's template. CVE-2026-74791, High. Write-up: https://offensive360.com/zerodays/cve-2026-74791-scriban/?utm_source=x&utm_medium=social&utm_campaign=daily&utm_content=20260909 #CVE #AppSec https://t.co/ZB63XYAlnt

    Post summary

    Scriban’s TemplateContext.Reset() flaw (CVE‑2026‑74791, high severity) allows tenant isolation bypass via cached templates; a write‑up with details is linked.

    0000049
    426 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-74791 Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts… https://www.cve.org/CVERecord?id=CVE-2026-74791 ----- Traducción: CVE-2026-74791 Scr… https://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-74791, describing a failure in Scriban's cache clearing, but does not provide any PoC, exploit, patch, or evidence of active exploitation.

    0000030
    99 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-74791 Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts… https://www.cve.org/CVERecord?id=CVE-2026-74791

    Post summary

    The text discloses a specific bug in Scriban where cached templates persist after reset in versions prior to 7.0.0, providing technical details but no evidence of exploitation or mitigation.

    000001.9K
    58.0K followersView on X

Explore more