What is CVE-2026-62996?
CVE-2026-62996 is a critical vulnerability in the Smarty PHP template engine. Insufficient restriction on stream resource handling in versions 5.0.0 through 5.8.4 can lead to remote code execution. Affected users should immediately update to the latest version.
Azərbaycanca: CVE-2026-62996 Smarty şablon mühərrikində aşkar edilmiş kritik zəiflikdir. Bu, stream resurs idarəetməsindəki məhdudiyyətsizlik səbəbindən uzaqdan kod icrasına imkan yarada bilər. Təsirə məruz qalan 5.0.0 - 5.8.4 versiyalarından istifadə edən təşkilatlar təcili olaraq ən son versiyaya yeniləməlidir.
FAQ2
Which versions of Smarty are affected by CVE-2026-62996?
This vulnerability affects Smarty versions 5.0.0 through 5.8.4.
What is the main threat of CVE-2026-62996?
The vulnerability can lead to remote code execution (RCE) due to insufficient restriction on stream resource handling.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.