CVE-2026-54390 Details
Description
JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. Attackers can exploit this flaw to read sensitive server-side values such as database credentials and encryption keys, and on versions 5.4.0 through 5.7.1, leverage registered Smarty modifiers including unserialize and file_get_contents to write a webshell to the web root and execute arbitrary commands as the web server user.
A server-side template injection vulnerability has been identified in JTL Shop versions 5.2.0 through 5.7.1. This vulnerability allows unauthenticated attackers to inject malicious template syntax, taking advantage of unsanitized user input sent to the Smarty template engine. Exploitation of this vulnerability could lead to the theft of sensitive server-side information, including database credentials and encryption keys. Furthermore, in JTL Shop versions 5.4.0 through 5.7.1, attackers could use registered Smarty modifiers such as 'unserialize' and 'file_get_contents' to write a web shell to the web root and execute arbitrary commands as the web server user.
JTL has released patches for versions 5.5.4, 5.6.2, and 5.7.2. For installations unable to upgrade to the latest point release, a back-patch covering versions 5.0.0 through 5.7.0 is available. After patching, it is recommended to rotate any exposed secrets, such as the Blowfish key and database password, as they should be considered compromised.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 18, 2026CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://forum.jtl-software.de/threads/jtl-shop-5-7-aktuell-5-7-2.246278/ | [email protected] | Release NotesVendor |
| https://sansec.io/research/jtl-shop-ssti-rce | [email protected] | AdvisoryRemedy |
| https://www.vulncheck.com/advisories/jtl-shop-server-side-template-injection-via-smarty-renderer | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1336 | Improper Neutralization of Special Elements Used in a Template Engine | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| JTL Shop | >= 5.2.0, <= 5.3.x >= 5.4.0, <= 5.7.1 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | CVE Modified | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | New CVE Received | [email protected] |
Volerion