CVE-2026-92718

Description

A flaw was found in Nuclei. An attacker can exploit a vulnerability in how Nuclei caches template signature verification. By replacing verified templates with malicious content and restoring the original modification time, an attacker can bypass signature checks, leading to the execution of arbitrary operating system commands.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Mitigation

Restrict write access to Nuclei template directories to prevent unauthorized modification of template files. Ensure that only trusted administrators have write permissions to these directories. For example, use `chmod` and `chown` to set appropriate permissions:

bash
# Example: Restrict write access to a template directory
sudo chmod -R 0755 /path/to/nuclei/templates
sudo chown -R root:root /path/to/nuclei/templates

This mitigation prevents attackers from replacing legitimate templates with malicious content, thereby preventing the signature bypass and arbitrary code execution.

Understanding the Weakness (CWE)

Access Control,Integrity,Confidentiality

Technical Impact: Gain Privileges or Assume Identity; Modify Application Data; Execute Unauthorized Code or Commands

An attacker could gain access to sensitive data and possibly execute unauthorized code.

Frequently Asked Questions

Want to get errata notifications? Sign up here.