PT-2026-69941 · Cachet · Cachet

·

CVE-2026-69118

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cachet versions prior to 2.4.2
Description An issue exists in incident template rendering that allows authenticated users to perform server-side template injection. By creating malicious incident templates using Blade directives or Twig filters, an attacker can execute arbitrary PHP code and system commands when incidents are created, leading to remote code execution as the web server process.
Recommendations Update Cachet to version 2.4.2 or later.

Exploit

Fix

RCE

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-69118

Affected Products

Cachet