CVE-2026-82531

LOWCVSS 9.2 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the regenerated PHP cache file, executing arbitrary PHP on include for remote code execution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-07: 210-07
Referenced assets3 URLs
Full discourse2 posts
  • mürrez@murrezsec

    🚨 CVE-2026-82531 — Critical RCE in Smarty Smarty template inheritance flaw allows arbitrary PHP code execution via forged SmartyNocache markers.. 🔴 CVSS 4.0: 9.2 Critical 🛠️ Fixed: 4.5.8 / 5.8.5 🔗 PoC: https://pocbit.org/pocs/cve-2026-82531 #CyberSecurity #Smarty #Exploit #PoC #InfoSec

    0001068
    631 followersView on X
  • dbugs@ptdbugs

    A PoC/exploit has been discovered for vulnerability CVE-2026-82531 PT ID: PT-2026-106715 Read on dbugs: https://dbu.gs/vulnerability/PT-2026-106715 Vendor: smarty-php Product: smarty Description: Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the regenerated PHP cache file, executing arbitrary PHP on include for remote code execution. Link: https://github.com/murrez/cve-2026-82531

    00000161
    3.6K followersView on X

Explore more