Junglewise Threat Intelligence

CVE-2026-25125: October CMS information disclosure in INI settings parser

CVE-2026-25125 · Severity: medium · CVSS 4.9 · Published 2026-04-14

Technologies: October CMS. Vendors: October CMS.

Executive brief

October CMS is a popular platform used for building and managing websites. A security flaw allows users with "Editor" permissions to trick the system into revealing sensitive server secrets, such as database passwords and cloud service keys. This could allow an attacker to gain full access to the site's database or other connected cloud infrastructure.

Technical details

A server-side information disclosure vulnerability exists in the October CMS INI settings parser due to the use of PHP's parse_ini_string() function, which supports ${} syntax for environment variable interpolation. An authenticated attacker with Editor-level access can inject patterns like ${APP_KEY} or ${DB_PASSWORD} into CMS page settings fields. When the page is saved and reopened, the system resolves these variables and displays their values, allowing for the exfiltration of sensitive secrets. This vulnerability specifically impacts installations where 'cms.safe_mode' is enabled (as PHP injection is otherwise possible) and has been patched in versions 3.7.14 and 4.1.10.

Affected products

  • October CMS October CMS < 3.7.14, >= 4.0.0, < 4.1.10

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory
  • 2026-04-14: patched

References

Related threats