CVE-2026-9558 is a critical server-side template injection vulnerability in Mautic's theme engine. The flaw arises because Mautic renders user-supplied Twig theme templates without enabling Twig sandboxing or enforcing strict restrictions on callable functions and template capabilities. An authenticated user with permission to create or upload themes can supply a malicious Twig template and trigger its rendering during theme preview or activation. Because the template is evaluated in an unsandboxed context, attacker-controlled Twig directives can access sensitive application context and, in some cases, reach PHP execution primitives, resulting in arbitrary code execution on the hosting server. The same flaw can also expose restricted system files and application configuration data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical server-side template injection / arbitrary code execution vulnerability in the Mautic theme engine caused by rendering uploaded Twig templates without Twig Sandbox restrictions.
A server-side template injection vulnerability in Mautic's theme engine that allows authenticated users with theme creation or upload permissions to execute arbitrary code on the hosting server or access restricted files and configuration settings.
A critical server-side template injection vulnerability in Mautic theme templates that allows authenticated users with theme creation permissions to achieve remote code execution and access restricted files due to unsandboxed Twig template rendering.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.