PT-2026-50772 · Jtl Shop+1 · Jtl-Shop+1

·

CVE-2026-54390

·

Published

2026-06-18

·

Updated

2026-06-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JTL Shop versions 5.2.0 through 5.7.1
Description Unauthenticated attackers can inject malicious template syntax because unsanitized user-supplied input is passed to the Smarty template engine, a tool used to generate dynamic web content. This allows for the retrieval of sensitive server-side information, including encryption keys and database credentials. In versions 5.4.0 through 5.7.1, attackers can use registered Smarty modifiers, specifically unserialize() and file get contents(), to write a webshell to the web root and execute arbitrary commands with the privileges of the web server user.
Recommendations Update to version 5.7.2 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54390

Affected Products

Jtl-Shop
Smarty