Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade directives or Twig filters that execute system commands when incidents are created, achieving remote code execution as the web server process.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 20:17
Updated : 2026-08-11 18:18
NVD link : CVE-2026-69118
Mitre link : CVE-2026-69118
CVE.ORG link : CVE-2026-69118
JSON object : View
Products Affected
No product.
