criticalCVSS 9.9Vulnerability

CVE-2026-9558

### Summary A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ### Impact An authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. ### Patched Versions This security issue has been addressed in the following releases: * **7.1.2** * **6.0.9** * **5.2.11** For users on Mautic 4.x, this fix is available in: * **4.4.20** via [ELTS](https://mautic.org/extended-long-term-support-elts/) Mautic strongly recommend upgrading to a patched version immediately. ### Workarounds There are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions (`core:themes:create`) to only highly trusted administrators.

Properties

severity
critical
summary
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
epss_score
0.00571
cvss_score
9.9
ghsa_published
2026-07-02T19:48:08Z
source_url
https://github.com/advisories/GHSA-9fx4-7cmj-47vg
ghsa_updated
2026-07-02T19:48:08Z
ghsa_id
GHSA-9fx4-7cmj-47vg
cve_id
CVE-2026-9558
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
is_ghsa_only
false
epss_percentile
0.44519

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/mautic/core

AFFECTS (1)

[Software]composer/mautic/core

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements Used in a Template Engine

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-9558 (CVSS 9.9) — Ninja Signal Threat Intelligence | Ninja Signal