CRITICAL
wintercms
CVE published 2026-08-25
CVE-2026-79774
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T16:17:29.060Z and has not been modified since then. CVE-2026-79774 is a critical vulnerability in Winter CMS versions before 1.2.13, involving an incomplete fix for a Twig sandbox escape vulnerability in System/Twig/SecurityPolicy. This allows authenticated backend users with template-editing per [truncated]