CVE-2026-69118 PUBLISHED

Cachet 2.4.1 Authenticated Server-Side Template Injection RCE

Assigner: VulnCheck
Reserved: 03.08.2026 Published: 10.08.2026 Updated: 10.08.2026

Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade directives or Twig filters that execute system commands when incidents are created, achieving remote code execution as the web server process.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor cachethq
Product cachet
Versions Default: unknown
  • affected from 0 to 2.4.1 (incl.)

Credits

  • George Chen finder

References

Problem Types

  • Improper Neutralization of Special Elements Used in a Template Engine CWE
  • Incorrect Authorization CWE