{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/microweber-cms-through-2.0.20/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-65693"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Microweber CMS through 2.0.20"],"_cs_severities":["high"],"_cs_tags":["server-side-template-injection","rce","cms","web-application","microweber"],"_cs_type":"advisory","_cs_vendors":["Microweber"],"content_html":"\u003cp\u003eCVE-2026-65693 identifies a critical server-side template injection (SSTI) vulnerability affecting Microweber CMS versions up to 2.0.20. The flaw allows an authenticated administrator to achieve arbitrary operating system command execution (RCE). This vulnerability stems from an unsandboxed Twig environment within the \u003ccode\u003eTwigView::render()\u003c/code\u003e function, which lacks proper security policies such as \u003ccode\u003eSandboxExtension\u003c/code\u003e or \u003ccode\u003eSecurityPolicy\u003c/code\u003e. Attackers can exploit this by injecting malicious Twig expressions, specifically those utilizing \u003ccode\u003efilter('system')\u003c/code\u003e, into mail template bodies. These malicious expressions are stored unsanitized in the database and are automatically executed whenever an application event triggers a mail dispatch, leading to a compromise of the underlying server. This vulnerability presents a significant risk to organizations using affected Microweber CMS instances, as it allows a privileged attacker to gain full control over the host system.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains authenticated administrative access to the Microweber CMS instance, potentially through compromised credentials or other means.\u003c/li\u003e\n\u003cli\u003eThe attacker navigates to the mail template editing section within the CMS administration panel.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious Twig expression, such as \u003ccode\u003e{{ T(filter('system')('command_to_execute')) }}\u003c/code\u003e, which leverages the unsandboxed \u003ccode\u003efilter('system')\u003c/code\u003e function to perform OS command execution.\u003c/li\u003e\n\u003cli\u003eThe malicious Twig expression is injected by the attacker into a mail template body, which the CMS then stores unsanitized in its backend database.\u003c/li\u003e\n\u003cli\u003eAt a later point, an application event occurs that triggers the dispatch of a mail using the compromised template. This could be a user registration, a password reset, or any other event that involves sending an email.\u003c/li\u003e\n\u003cli\u003eDuring the mail dispatch process, the vulnerable \u003ccode\u003eTwigView::render()\u003c/code\u003e function attempts to render the template. The unsandboxed Twig environment processes the malicious \u003ccode\u003efilter('system')\u003c/code\u003e expression.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003efilter('system')\u003c/code\u003e function executes the embedded operating system command with the privileges of the web server process, leading to arbitrary OS command execution on the underlying server.\u003c/li\u003e\n\u003cli\u003eThe attacker can then use the executed command to establish further persistence, exfiltrate data, or completely compromise the host system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-65693 grants an authenticated administrator arbitrary operating system command execution on the server hosting the Microweber CMS. This allows attackers to take full control of the server, leading to severe consequences such as data theft, defacement of the website, installation of malware, establishment of backdoors, or use of the compromised server as a platform for further attacks. The vulnerability affects Microweber CMS through version 2.0.20, impacting potentially numerous organizations globally that use this platform. The compromise of administrator credentials is a prerequisite, highlighting the importance of robust authentication and least privilege principles.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-65693 by updating Microweber CMS to a version beyond 2.0.20 immediately.\u003c/li\u003e\n\u003cli\u003eImplement strong authentication measures, such as multi-factor authentication (MFA), for all administrative accounts to mitigate the risk of initial administrative access.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP POST requests to administrative endpoints that may contain unusual or suspicious template content, particularly strings like \u0026quot;filter('system')\u0026quot;.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring on critical Microweber CMS files and database tables to detect unauthorized modifications, especially to mail templates.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T16:24:47Z","date_published":"2026-07-24T16:24:47Z","id":"https://feed.craftedsignal.io/briefs/2026-07-microweber-ssti/","summary":"An authenticated administrator in Microweber CMS through version 2.0.20 is vulnerable to server-side template injection due to an unsandboxed Twig environment, allowing for arbitrary OS command execution by injecting malicious Twig expressions into mail templates, which are executed automatically upon mail dispatch and can compromise the underlying server.","title":"Microweber CMS Server-Side Template Injection Leads to RCE (CVE-2026-65693)","url":"https://feed.craftedsignal.io/briefs/2026-07-microweber-ssti/"}],"language":"en","title":"CraftedSignal Threat Feed - Microweber CMS Through 2.0.20","version":"https://jsonfeed.org/version/1.1"}