CVE-2026-82531 — Smarty Template Cache Poisoning RCE (SmartyNocache / extends)
October 7, 2026 · 71 views
smarty-php/smarty <4.5.8 and 5.0.0–5.8.4: extends/inheritance + cache regen with null nocache_hash lets forged assign() data inject SmartyNocache markers into cache PHP → include() RCE. CWE-94, CVSS 4.0 9.2 Critical (AT:P). Fixed 4.5.8 / 5.8.5. Python PoC: check/exploit/payload, Docker lab 5.8.4, hits.txt & exploited.txt. Marker POCBIT-82531-OK.
Description
Overview
CVE-2026-82531 — Smarty PHP template engine (smarty-php/smarty) — code injection (CWE-94) via forged SmartyNocache markers in template cache files when using extends: / block inheritance.
| | | |---|---| | Affected | < 4.5.8; 5.0.0 – 5.8.4 | | Fixed | 4.5.8, 5.8.5 | | CVSS 4.0 | 9.2 Critical — AT:P (caching + extends + user-controlled assign) | | CVSS 3.1 | 8.1 High | | Verify marker | POCBIT-82531-OK (base64 command output in body) |
After a PHP worker loads compiled templates from disk, nocache_hash can be null during cache regeneration. Smarty_Internal_Runtime_UpdateCache then builds a regex with an empty alternative, so attacker assign() data can forge /*%%SmartyNocache:%%*/ <?php ... ?> /*/%%SmartyNocache:%% into the cache PHP file. The next include() of that cache executes injected PHP.
PoC page: https://pocbit.org/pocs/cve-2026-82531
GitHub: murrez/CVE-2026-82531
CVE.org: CVE-2026-82531
GHSA: GHSA-3w63-v7pm-cq9x
Exploit chain (PoC exploit)
| Phase | Action |
|-------|--------|
| 1 Warm | Benign assign → compile + initial cache |
| 2 Clear | Drop cache files (compiled templates remain); lab: ?lab_clear_cache=1 |
| 3 Poison | name= forged SmartyNocache + shell_exec |
| 4 Trigger | Benign request → include() runs PHP; body POCBIT-82531-OK: + base64 |
Production targets need caching on, extends templates, user-controlled assign, and a cache miss while compile dir is warm (TTL, restart, admin flush).
Bundled tool (Python 3 + Docker lab)
Download cve-2026-82531.py — extracts poc.py, requirements.txt, docker-compose.yml, and lab/ tree.
python cve-2026-82531.py
pip install -r requirements.txt
docker compose up --build -d
python poc.py check http://127.0.0.1:8088
python poc.py exploit --url http://127.0.0.1:8088 -c "id"
python poc.py exploit -i targets.example.txt -w 10 -c id
python poc.py payload -c "id"
After patching: delete/regenerate all template cache files.
Remediation
- Upgrade Smarty to ≥ 4.5.8 or ≥ 5.8.5 (Composer lockfile audit).
- Flush template cache after upgrade—not only compiled templates.
- Inventory apps embedding Smarty (CMS, shop themes, custom PHP).
Legal and ethical use
Authorized security testing only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- WordPressCVE-2026-96349critical
CVE-2026-96349 — WordPress SiteSkite ≤2.1.8 API-Key Autologin + MCP eval() RCE Chain
SiteSkite WordPress plugin ≤2.1.8: long-lived API key acts as unauthenticated admin bearer via ?token= autologin; REST/admin-ajax MCP abilities run siteskite_execute_php (eval) and file write. CVSS 10.0 Critical (CWE-94). Fixed in 2.2.0. Python PoC: check (readme ≤2.1.8), exploit with API key, mass hits/exploited, --lab. Marker POCBIT-96349-OK.
- JoomlaCVE-2026-102425critical
CVE-2026-102425 — Joomla Balbooa Forms (com_baforms) Field Shortcode → Unauthenticated RCE
Balbooa Forms for Joomla 1.0.0–2.4.3.3: when a public form runs PHP-after-submission via eval(), field shortcodes are replaced with raw visitor input inside double-quoted PHP — classic ";breakout;// → RCE. CVSS 4.0 9.5 Critical (AT:P). Fixed in 2.4.3.4. Not CVE-2026-67364. Python PoC: version + public form detect, check/exploit, up.php drop, interactive + mass -j.
- Web appCVE-2026-85520critical
CVE-2026-85520 — PrestaShop gmfeed (MyPresta) Unauthenticated Arbitrary File Write → RCE
Google Merchant Center Feed (gmfeed) for PrestaShop ≤2.3.9: unauthenticated arbitrary file write on modules/gmfeed/feed.php when Save-to-file / URL export is enabled — attacker controls filename, path, extension, and body → PHP webshell → RCE. CVSS 9.3 Critical. Fixed in 2.3.10+ (2.4.1+ recommended). Python PoC: check, aggressive probe, exploit with marker stub, mass --list -j.
- Web appCVE-2026-82384critical
CVE-2026-82384 — Apache Roller 6.1.5 XML-RPC Pre-Auth Java Deserialization
Unauthenticated Java deserialization (CWE-502) on Apache Roller 6.1.5 legacy XML-RPC servlet: enabledForExtensions allows ex:serializable before Blogger/MetaWeblog auth; mapping stays active even when XML-RPC is disabled in UI. Pre-auth RCE via attacker-controlled serialized objects (ysoserial/classpath gadgets). Fixed in 6.1.6+. CVSS 9.8 Critical. Python PoC: check, probe-deser, exploit, mass -j.