CVE-2026-22692 Details
Description
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twig safe mode feature (CMS_SAFE_MODE). Certain methods on the collect() helper were not properly restricted, allowing authenticated users with template editing permissions to bypass sandbox protections. Exploitation requires authenticated backend access with CMS template editing permissions and only affects installations with CMS_SAFE_MODE enabled (disabled by default). This issue has been fixed in versions 3.7.13 and 4.1.5. To workaround this issue, users can disable CMS_SAFE_MODE if untrusted template editing is not required, and restrict CMS template editing permissions to fully trusted administrators only.
A sandbox bypass vulnerability has been identified in October CMS versions prior to 3.7.13 and versions 4.0.0 through 4.1.4. The issue resides in the optional Twig safe mode feature, 'CMS_SAFE_MODE', where certain methods on the 'collect()' helper were not adequately restricted. This flaw allows authenticated users with template editing permissions to bypass sandbox protections. The vulnerability only affects installations with 'CMS_SAFE_MODE' enabled, which is disabled by default, and requires authenticated backend access with CMS template editing permissions.
Users can upgrade to October CMS versions 3.7.13 or 4.1.5, where this vulnerability has been patched. If an immediate upgrade is not possible, 'CMS_SAFE_MODE' can be disabled if untrusted template editing is not needed, and CMS template editing permissions can be restricted to fully trusted administrators only.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/octobercms/october/security/advisories/GHSA-m5qg-jc75-4jp6 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
| CWE-693 | Protection Mechanism Failure | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| octobercms october | < 3.7.13 >= 4.0.0, < 4.1.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | Initial Analysis | [email protected] |
| Apr 14, 2026 | New CVE Received | [email protected] |