PT-2026-82686 · Silverstripe · Advanced Workflow

·

CVE-2026-54718

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Silverstripe Advanced Workflow versions prior to 6.4.5 Silverstripe Advanced Workflow versions prior to 7.1.3 Silverstripe Advanced Workflow versions prior to 7.2.1
Description An attacker with permissions to author the advanced workflow email template can execute arbitrary code on the server. This occurs when a specially crafted server-side template payload is placed in NotifyUsersWorkflowAction.EmailTemplate. The issue is triggered when the SSTemplateParser (the Silverstripe template engine) renders the field, leading to PHP evaluation.
Recommendations Update to version 6.4.5. Update to version 7.1.3. Update to version 7.2.1.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54718
GHSA-39MM-RWM3-29JP

Affected Products

Advanced Workflow