Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-82531: Smarty templates may let attackers run PHP code
CVE-2026-82531 · published 4 days ago
Summary
Versions of Smarty before 4.5.8 and 5.x before 5.8.5 can fail to clean up a cache marker when templates inherit from each other. This lets a malicious user insert specially crafted data that becomes part of the generated PHP file, potentially allowing the attacker to execute code on the server. Update Smarty to the latest version or apply the vendor’s patch to fix the issue.
What to do
- Update smarty-php smarty to version 4.5.8 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | smarty-php | smarty | < 4.5.8 |
| Debian:12 | debian | smarty3 | All versions |
| Debian:12 | debian | smarty4 | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | smarty3 | All versions |
| Ubuntu:24.04:LTS | canonical | smarty4 | All versions |
Original advisory text
Smarty before 4.5.8 and 5.x before 5.8.5 PHP Code Injection via extends: Inheritance Cache
Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the regenerated PHP cache file, executing arbitrary PHP on include for remote code execution.
References
- https://ubuntu.com/security/CVE-2026-82531 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-82531 Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82531... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-82531 Vendor Advisory
- https://github.com/smarty-php/smarty Product
- https://github.com/smarty-php/smarty/commit/c0fdd4824aca4f67e814b50703cfee1dfde4...
- https://github.com/smarty-php/smarty/commit/1cba51cb813563eb61d963c83d28cd59f26b...
- https://github.com/smarty-php/smarty/releases/tag/v5.8.5
- https://github.com/smarty-php/smarty/releases/tag/v4.5.8
- https://www.vulncheck.com/advisories/smarty-before-4.5.8-and-5-x-before-5.8.5-ph...
- https://github.com/smarty-php/smarty/security/advisories/GHSA-3w63-v7pm-cq9x
- https://security-tracker.debian.org/tracker/CVE-2026-82531 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.2
Critical
Type
CWE-94Code Injection
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-82531 · NVD
CVE-2026-82531 · MITRE
DEBIAN-CVE-2026-82531 · OSV
CVE-2026-82531 · OSV
GHSA-3w63-v7pm-cq9x · GHSA
UBUNTU-CVE-2026-82531 · OSV
Track software like this
Free during beta