---
id: CVE-2026-92718
title: >-
  Nuclei versions before 3.11.1 cache template signature verification based only
  on file modification time without content checksums
summary: >-
  Nuclei versions before 3.11.1 cache template signature verification based only
  on file modification time without content checksums. Attackers can replace
  verified templates with unsigned malicious content and restore the original
  modific…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-347
vendor: projectdiscovery
product: nuclei
affected:
  - nuclei >= 3.7.0 < 3.11.1
published: '2026-09-16'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:04:40.340'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92718'
references:
  - url: 'https://github.com/projectdiscovery/nuclei'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/projectdiscovery/nuclei/blob/v3.11.0/pkg/catalog/index/metadata.go#L78-L84
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/projectdiscovery/nuclei/blob/v3.11.0/pkg/templates/compile.go#L610-L624
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/projectdiscovery/nuclei/commit/9de96e4dda5a03da963b9ae6582f03ea55791a76
    label: disclosure@vulncheck.com
  - url: 'https://github.com/projectdiscovery/nuclei/issues/7663'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nuclei-from-3.7.0-before-3.11.1-template-signature-bypass-via-modification-time-only-cache
    label: disclosure@vulncheck.com
  - url: 'https://github.com/projectdiscovery/nuclei/issues/7663'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-92718.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-92718'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-92718'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
  - exploit-available
epss: 0.00121
epssPercentile: 0.01679
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-18T18:15:17.532307Z'
ingestedAt: '2026-09-16T18:01:17.460Z'
---

## Overview

Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modification time to bypass signature checks and execute arbitrary operating system commands.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-92718.json)
