---
id: CVE-2026-79774
title: >-
  Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox
  escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated
  backend users with template-editing permissions to bypass sandbox
  restrictions.…
summary: >-
  Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox
  escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated
  backend users with template-editing permissions to bypass sandbox
  restrictions.…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-693
vendor: wintercms
product: winter
affected:
  - winter >= 1.2.7 < 1.2.13
published: '2026-08-25'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:45.083'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79774'
references:
  - url: >-
      https://github.com/wintercms/winter/commit/725bbcda232466f7f71381c271c6916573d576e6
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/wintercms/winter/security/advisories/GHSA-8cfw-pcwh-v63w
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/winter-cms-before-twig-sandbox-escape-via-securitypolicy
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-26T15:57:18.454449Z'
epss: 0.00808
epssPercentile: 0.55527
ingestedAt: '2026-10-08T16:52:14.726Z'
---

## Overview

Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers can exploit method forwarding through Eloquent models and query builders using methods like saveQuietly(), deleteQuietly(), increment(), decrement(), and newQuery() to read and modify arbitrary database records, execute arbitrary SQL, and achieve remote code execution by injecting PHP into template code sections.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
