CVE-2026-92718
Description
A flaw was found in Nuclei. An attacker can exploit a vulnerability in how Nuclei caches template signature verification. By replacing verified templates with malicious content and restoring the original modification time, an attacker can bypass signature checks, leading to the execution of arbitrary operating system commands.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Mitigation
Restrict write access to Nuclei template directories to prevent unauthorized modification of template files. Ensure that only trusted administrators have write permissions to these directories. For example, use `chmod` and `chown` to set appropriate permissions:
bash
# Example: Restrict write access to a template directory
sudo chmod -R 0755 /path/to/nuclei/templates
sudo chown -R root:root /path/to/nuclei/templates
This mitigation prevents attackers from replacing legitimate templates with malicious content, thereby preventing the signature bypass and arbitrary code execution.
Understanding the Weakness (CWE)
Access Control,Integrity,Confidentiality
Technical Impact: Gain Privileges or Assume Identity; Modify Application Data; Execute Unauthorized Code or Commands
An attacker could gain access to sensitive data and possibly execute unauthorized code.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.