cvesecurityvulnerability
CVE-2026-69118: Cachet Status Page Server-Side Template Injection to RCE
Cachet through 2.4.1 allows authenticated users to execute arbitrary PHP code via server-side template injection in incident template rendering. CVSS 8.7 HIGH. No fix for 2.x branch.