A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

There are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions (core:themes:create) to only highly trusted administrators.

History

Fri, 29 May 2026 11:45:00 +0000

Type Values Removed Values Added
Title SSTI in Mautic Theme Engine Allows Authenticated Remote Code Execution
First Time appeared Mautic
Mautic mautic
Vendors & Products Mautic
Mautic mautic

Fri, 29 May 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 May 2026 10:30:00 +0000

Type Values Removed Values Added
Description A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.
Weaknesses CWE-1336
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mautic

Published:

Updated: 2026-05-29T10:49:06.099Z

Reserved: 2026-05-26T08:36:52.218Z

Link: CVE-2026-9558

cve-icon Vulnrichment

Updated: 2026-05-29T10:49:00.571Z

cve-icon NVD

Status : Deferred

Published: 2026-05-29T11:16:17.980

Modified: 2026-05-29T15:39:34.620

Link: CVE-2026-9558

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T11:30:42Z

Weaknesses