Mautic Theme Templates: Server-Side Template Injection to Full Admin Takeover
CVE-2026-9558
Mautic renders uploaded theme templates through Twig without a sandbox. We used that to run system commands, steal the application’s database credentials, …
4 CVEs analysed. Honest verdicts only.
Mautic renders uploaded theme templates through Twig without a sandbox. We used that to run system commands, steal the application’s database credentials, …
A hardcoded fallback JWT signing key, used whenever the operator never sets JWT_SECRET, allows any remote attacker to forge a valid authentication token for …
The bypass is real and reproducible. A POST request to a resource protected by a split web-resource-collection bypasses authentication entirely. But the …
Even if digest hashes match, authentication still fails. This post documents why CVE-2026-43512 is a confirmed bug but not a confirmed bypass.