Description
October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. The Laravel session store was exposed to Twig with unrestricted method access, and raw SQL methods reachable through Eloquent's `__call` forwarding were not blocked across the full builder chain. When combined, a backend user with CMS markup editing access could read arbitrary database values via raw SQL expressions and write to the backend authentication session key, forging a backend session as another existing user. The scope of impact is narrow. Safe Mode is a niche feature, primarily used for demo installations and multi-tenant or shared-editor scenarios where untrusted users are deliberately granted access to the CMS markup editor. Standard production deployments do not enable Safe Mode, because under normal October CMS guidance backend access - including markup editing - is restricted to trusted administrators, and direct PHP injection through markup is already possible without Safe Mode in that configuration. This issue only affects sites that meet all of the following conditions: `cms.safe_mode` is enabled (a deliberate opt-in for demos or untrusted-editor scenarios; the site has at least one backend user with CMS markup editing access who is not intended to be trusted as a full administrator; and the site has at least one existing superuser account whose session the lower-privileged user can impersonate. The vulnerability has been patched in v3.7.17 and v4.2.21. The Laravel session store is now wrapped in a proxy that exposes only an explicit subset of read/write methods and rejects writes to reserved session key prefixes (`admin_auth`, `october_auth`, `login_*`, `_token`, and other framework internals). Raw SQL and subquery methods (`selectRaw`, `whereRaw`, `orderByRaw`, `joinSub`, and related) are now blocked on `Query\Builder`, `Eloquent\Builder`, and `Eloquent\Model` so the blocklist is consistent across the `__call` forwarding chain. All sites that enable `cms.safe_mode` are encouraged to upgrade to the latest patched version. A workaround is available. Restrict CMS markup editing access to fully trusted administrators only - the standard October CMS recommendation for any deployment. Note that disabling `cms.safe_mode` is not a workaround; Safe Mode is the boundary this issue affects, and disabling it removes the only sandbox between markup editors and the server.
Published: 2026-09-14
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Session Hijacking and Data Exposure
Action: Patch Immediately
AI Analysis

Impact

October CMS uses a Twig sandbox when cms.safe_mode is enabled. In affected versions prior to 3.7.17 and 4.2.21, a backend user with CMS markup editing rights can exploit an unrestricted session store and raw SQL access to read arbitrary database values and write to the authentication session key. This allows the attacker to forge a session as any existing user, granting unauthorized administrative access and exposure of confidential data. The flaw is confined to sites that deliberately enable Safe Mode for demo or untrusted‑editor scenarios, making the overall impact narrow but serious for this niche use case.

Affected Systems

OctoberCMS System module, versions earlier than 3.7.17 (for the 3.x line) and 4.2.21 (for the 4.x line). The vulnerability is only triggered when cms.safe_mode is enabled and a backend user with CMS markup editing permissions has access, and when at least one superuser account exists that can be impersonated.

Risk and Exploitability

The CVSS score of 3.3 reflects low severity, and the EPSS score is reported as < 1%, indicating a very low likelihood of exploitation in the general population. The risk is not listed in the CISA KEV catalog. Exploitation requires a site to have Safe Mode enabled, a backend user with markup editing rights, and a superuser account; if these conditions are met, the attacker can read database values and hijack sessions. Consequently, the overall risk is considered low for most deployments but significant for environments that intentionally use Safe Mode for untrusted editors.

Generated by OpenCVE AI on September 20, 2026 at 23:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to October CMS version 3.7.17 or later, or version 4.2.21 or later, where the session store and raw SQL methods are properly restricted.
  • Limit CMS markup editing privileges to trusted administrators only, ensuring that untrusted users cannot leverage the sandbox.
  • If Safe Mode is not required for your deployment, disable the cms.safe_mode configuration, but always apply the patch regardless of the setting.

Generated by OpenCVE AI on September 20, 2026 at 23:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xv9m-fm3w-8w5x October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Octobercms
Octobercms system
Vendors & Products Octobercms
Octobercms system

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. The Laravel session store was exposed to Twig with unrestricted method access, and raw SQL methods reachable through Eloquent's `__call` forwarding were not blocked across the full builder chain. When combined, a backend user with CMS markup editing access could read arbitrary database values via raw SQL expressions and write to the backend authentication session key, forging a backend session as another existing user. The scope of impact is narrow. Safe Mode is a niche feature, primarily used for demo installations and multi-tenant or shared-editor scenarios where untrusted users are deliberately granted access to the CMS markup editor. Standard production deployments do not enable Safe Mode, because under normal October CMS guidance backend access - including markup editing - is restricted to trusted administrators, and direct PHP injection through markup is already possible without Safe Mode in that configuration. This issue only affects sites that meet all of the following conditions: `cms.safe_mode` is enabled (a deliberate opt-in for demos or untrusted-editor scenarios; the site has at least one backend user with CMS markup editing access who is not intended to be trusted as a full administrator; and the site has at least one existing superuser account whose session the lower-privileged user can impersonate. The vulnerability has been patched in v3.7.17 and v4.2.21. The Laravel session store is now wrapped in a proxy that exposes only an explicit subset of read/write methods and rejects writes to reserved session key prefixes (`admin_auth`, `october_auth`, `login_*`, `_token`, and other framework internals). Raw SQL and subquery methods (`selectRaw`, `whereRaw`, `orderByRaw`, `joinSub`, and related) are now blocked on `Query\Builder`, `Eloquent\Builder`, and `Eloquent\Model` so the blocklist is consistent across the `__call` forwarding chain. All sites that enable `cms.safe_mode` are encouraged to upgrade to the latest patched version. A workaround is available. Restrict CMS markup editing access to fully trusted administrators only - the standard October CMS recommendation for any deployment. Note that disabling `cms.safe_mode` is not a workaround; Safe Mode is the boundary this issue affects, and disabling it removes the only sandbox between markup editors and the server.
Title October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
Weaknesses CWE-269
CWE-284
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Octobercms System
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T17:36:25.393Z

Reserved: 2026-05-15T23:26:58.308Z

Link: CVE-2026-46696

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:47.687

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-46696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:00:08Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control