Junglewise Threat Intelligence

CVE-2026-9558: Mautic Server-Side Template Injection in theme engine

CVE-2026-9558 · Severity: critical · CVSS 9.9 · Published 2026-05-29

Technologies: Mautic. Vendors: Mautic.

Executive brief

Mautic, an open-source marketing automation platform, contains a vulnerability in its theme management system. An authorized user with permissions to upload or create themes can exploit this to execute malicious commands on the server. This could lead to a total system takeover, unauthorized access to sensitive customer data, or complete service disruption.

Technical details

A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine due to improper neutralization of special elements in Twig templates (CWE-1336). The platform renders uploaded templates without a restricted sandbox or function limitations. An authenticated attacker with 'core:themes:create' permissions can upload a crafted Twig template to achieve Remote Code Execution (RCE) or access restricted system files. The vulnerability is reachable over the network and has been patched in versions 7.1.2, 6.0.9, 5.2.11, and 4.4.20 (via ELTS).

Affected products

  • Mautic Mautic >= 1.3.0, < 4.4.13; >= 5.0.0, < 5.2.11; >= 6.0.0, < 6.0.9; >= 7.0.0, < 7.1.2

Timeline

  • 2026-05-29: disclosed
  • 2026-07-02: advisory

References

Related threats