A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.
History

Fri, 29 May 2026 11:45:00 +0000

Type Values Removed Values Added
Title SSTI in Mautic Theme Engine Allows Authenticated Remote Code Execution
First Time appeared Mautic
Mautic mautic
Vendors & Products Mautic
Mautic mautic

Fri, 29 May 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 May 2026 10:30:00 +0000

Type Values Removed Values Added
Description A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.
Weaknesses CWE-1336
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mautic

Published: 2026-05-29T10:01:36.019Z

Updated: 2026-05-29T10:49:06.099Z

Reserved: 2026-05-26T08:36:52.218Z

Link: CVE-2026-9558

cve-icon Vulnrichment

Updated: 2026-05-29T10:49:00.571Z

cve-icon NVD

Status : Deferred

Published: 2026-05-29T11:16:17.980

Modified: 2026-05-29T15:39:34.620

Link: CVE-2026-9558

cve-icon Redhat

No data.