← Back to browse · API

CVE-2026-9558

Severity
CRITICAL
CVSS
9.9
EPSS
0.00571
Risk score
39.8
CISA KEV
No
PoC
Yes
Published
2026-05-29
Modified
2026-05-29
First seen
2026-08-05
Aliases
EUVD-2026-33276, GHSA-9FX4-7CMJ-47VG
Products
-
Sources
nvd CVE-2026-9558
euvd EUVD-2026-33276
packetstorm afa99f934699fa651aa3a1a6|CVE-2026-9558

Description

A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.

References