CVE-2026-82531: Improper Control of Generation of Code ('Code Injection') in smarty-php smarty
Description
Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the regenerated PHP cache file, executing arbitrary PHP on include for remote code execution.
CVSS v4.0
Score 9.2critical
Affected software
smarty-php
smarty
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-82531 is a critical code injection vulnerability in smarty-php's Smarty template engine. The issue arises because the top-level nocache_hash is not restored during extends:/multi-component template inheritance, leaving it null. Attackers can exploit this by supplying assigned data with a forged SmartyNocache marker, which is copied verbatim into the regenerated PHP cache file. This results in arbitrary PHP code execution when the cache file is included, enabling remote code execution.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary PHP code on the server running vulnerable Smarty versions. This can lead to full system compromise, data theft, or service disruption. The CVSS 4.0 score is 9.2 (critical), reflecting the high impact and ease of exploitation without user interaction or privileges.
Mitigation Recommendations
A fix is available in Smarty versions 4.5.8 and 5.8.5. Users should upgrade to these or later versions to remediate the vulnerability. No vendor advisory content was provided, but the affected versions and fixed versions are clearly stated. Until patched, avoid using untrusted data in assigned Smarty variables that could contain nocache markers.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-29T17:20:57.082Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac4eab52cdf04f656aa0da5
Added to database: 10/06/2026, 12:33:57 UTC
Last enriched: 10/06/2026, 12:48:13 UTC
Last updated: 10/06/2026, 18:57:28 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.