Sceawere

Vulnerability Detail

CVE-2026-82531UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Smarty Remote Code Injection

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
12h ago
Vendor
smarty-php
Product
smarty
Attack Type
Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the regenerated PHP cache file, executing arbitrary PHP on include for remote code execution.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-10-06T13:16:50.180Z",
  "pubdate": "2026-10-06T13:16:50.180Z",
  "executiveSummary": "Smarty versions before 4.5.8 and 5.x before 5.8.5 are susceptible to a critical code injection vulnerability. The flaw exists within the template inheritance mechanism, specifically when processing 'extends' tags with multi-component inheritance. An attacker can exploit this by supplying maliciously crafted data containing a forged 'SmartyNocache' marker. Because the system fails to correctly restore the 'nocache_hash' during the template regeneration process, the input is treated as trusted code and written directly into the cached PHP file. Successful exploitation allows for arbitrary PHP execution on the server, resulting in complete system compromise, unauthorized data access, and potential remote control of the host application. The risk is considered high due to the lack of required authentication for triggering the vulnerable code path if user-supplied data reaches the template engine.",
  "technicalDetails": "The vulnerability resides in the core template inheritance logic of the Smarty engine, specifically involving the 'extends:' resource handler. The root cause is a state management failure where the 'nocache_hash' variable is improperly handled during the recursive processing of template inheritance chains. In a normal operating state, 'nocache_hash' serves as a unique identifier used to protect dynamic, non-cached sections of a template. However, when complex 'extends' tags are utilized, the engine fails to restore the correct top-level 'nocache_hash', effectively resetting it to a null value during the rendering cycle.\nThis state inconsistency creates a security hole during the creation or regeneration of the PHP cache files. Smarty employs a mechanism to identify non-cached content by injecting specific markers, typically involving 'SmartyNocache' tags, into the compiled PHP output. When the 'nocache_hash' is null or improperly managed, the engine becomes unable to correctly sanitize or escape content passed via template variables that happen to contain these markers.\nThe attack flow begins when an attacker provides input to the application that is subsequently assigned to a Smarty template variable. The attacker crafts the input to include a forged 'SmartyNocache' marker sequence. When the Smarty compiler processes this template, the lack of a proper 'nocache_hash' causes the compiler to mistake the attacker's supplied marker as a legitimate internal non-cached block. Consequently, the compiler performs a verbatim write of the attacker-supplied PHP payload into the generated template cache file.\nUpon the next inclusion of this cached template, the web server executes the resulting PHP file, which now contains the attacker's embedded code. Because this occurs at the PHP execution layer, the injected code runs with the privileges of the web server process. This results in unrestricted Remote Code Execution (RCE). The vulnerability does not require authentication to the Smarty instance itself, provided the application allows arbitrary user input to be passed to vulnerable template inheritance calls. The exploit is persistent as long as the malicious cache file remains on the disk, allowing for recurring execution until the cache is cleared or the underlying template is updated."
}
CVE-2026-82531: Smarty Remote Code Injection (HIGH Severity, CVSS: 8.1) | Sceawere