OVERVIEW CVE-2026-22692 is a sandbox bypass vulnerability affecting October CMS versions prior to 3.7.13 and versions 4.0.0 through 4.1.4. The vulnerability exists in the optional Twig safe mode feature (CMS_SAFE_MODE), where certain methods on the collect() helper were not properly restricted, allowing authenticated users with template editing permissions to circumvent sandbox protections. This issue only impacts installations with CMS_SAFE_MODE explicitly enabled, which is disabled by default. SEVERITY The vulnerability carries a CVSS score of 6.8 (Medium) with a network attack vector, low complexity, and high privilege requirements. While exploitation demands authenticated backend access with CMS template editing permissions, successful bypass could result in high confidentiality impact. The limited EPSS score of 0.000170 suggests minimal prevalence in real-world environments at this time. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence watch lists. No publicly available exploit code has been reported. Patches are available in October CMS versions 3.7.13 and 4.1.5, and users can implement workarounds by disabling CMS_SAFE_MODE and restricting template editing permissions to trusted administrators only.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.7.13CPE matchmatch criteria | cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.1.5CPE matchmatch criteria | cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.