Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-82531: Smarty templates may let attackers run PHP code

CVE-2026-82531 · published 4 days ago
Summary

Versions of Smarty before 4.5.8 and 5.x before 5.8.5 can fail to clean up a cache marker when templates inherit from each other. This lets a malicious user insert specially crafted data that becomes part of the generated PHP file, potentially allowing the attacker to execute code on the server. Update Smarty to the latest version or apply the vendor’s patch to fix the issue.

What to do
  • Update smarty-php smarty to version 4.5.8 or later.
Affected software
Ecosystem VendorProductAffected versions
– smarty-php smarty < 4.5.8
Debian:12 debian smarty3 All versions
Debian:12 debian smarty4 All versions
Ubuntu:Pro:16.04:LTS canonical smarty3 All versions
Ubuntu:24.04:LTS canonical smarty4 All versions
Original advisory text
Smarty before 4.5.8 and 5.x before 5.8.5 PHP Code Injection via extends: Inheritance Cache
Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the regenerated PHP cache file, executing arbitrary PHP on include for remote code execution.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-94Code Injection
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta