What is CVE-2026-62992?
CVE-2026-62992 is a symlink vulnerability in the Smarty PHP template engine, where Security::_checkDir() does not fully resolve symbolic links before validating paths. This could allow attackers to access files outside the configured secure directory. Affected versions are before 4.5.7 on the 4.x line and before 5.8.2, requiring an immediate update.
Azərbaycanca: CVE-2026-62992 Smarty şablon mühərrikində simvolik keçid (symlink) zəifliyidir. Bu boşluq, hücumçulara _checkDir() funksiyasının keçidləri tam həll etməməsi səbəbindən qorunan qovluq xaricindəki fayllara daxil olmağa imkan verə bilər. 4.x xəttində 4.5.7 və əsas xəttdə 5.8.2 versiyalarından əvvəlki versiyalar təsirlənir, ona görə də dərhal yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which function in Smarty contains the flaw that causes CVE-2026-62992?
The vulnerability stems from the Security::_checkDir() function not fully resolving symbolic links.
Which versions of Smarty are affected by CVE-2026-62992?
Versions before 4.5.7 on the 4.x line and before 5.8.2 on the main line are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.