Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-22692

24
FAUCET Score

OVERVIEW CVE-2026-22692 is a sandbox bypass vulnerability affecting October CMS versions prior to 3.7.13 and versions 4.0.0 through 4.1.4. The vulnerability exists in the optional Twig safe mode feature (CMS_SAFE_MODE), where certain methods on the collect() helper were not properly restricted, allowing authenticated users with template editing permissions to circumvent sandbox protections. This issue only impacts installations with CMS_SAFE_MODE explicitly enabled, which is disabled by default. SEVERITY The vulnerability carries a CVSS score of 6.8 (Medium) with a network attack vector, low complexity, and high privilege requirements. While exploitation demands authenticated backend access with CMS template editing permissions, successful bypass could result in high confidentiality impact. The limited EPSS score of 0.000170 suggests minimal prevalence in real-world environments at this time. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence watch lists. No publicly available exploit code has been reported. Patches are available in October CMS versions 3.7.13 and 4.1.5, and users can implement workarounds by disabling CMS_SAFE_MODE and restricting template editing permissions to trusted administrators only.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.7.13CPE matchmatch criteria
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*
>= 4.0.0, < 4.1.5CPE matchmatch criteria
cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.9MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.40%
Probability of exploitation in next 30 days
EPSS Percentile
32.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0040 is in the 27th percentile among its peer group of 3,566 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

composerpatch availablevia ghsa
Product: october/rainFixed in: 4.1.5
composerpatch availablevia ghsa
Product: october/rainFixed in: 3.7.13
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-m5qg-jc75-4jp6medium

October Rain has a Twig Sandbox Bypass via Collection Methods

Apr 14, 2026

References

github.com / octobercms/october/security/advisories/GHSA-m5qg-jc75-4jp6
Vendor Advisory