CVE-2026-82531EPSS p56.1%
CVE-2026-82531CVE-2026-82531
Description
Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the regenerated PHP cache file, executing arbitrary PHP on include for remote code execution.
Scoring
| CVSS | 8.1 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.82% probability of exploitation · percentile 56.1% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-06 |