PatchSiren cyber security CVE debrief
CVE-2026-79773 wintercms CVE debrief
Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter. This allows authenticated users with cms.manage_assets permission to disclose arbitrary server-readable files by placing =include or =require directives in theme JavaScript assets. The combined output served through the combine route becomes readable by unauthenticated visitors, exposing sensitive information such as application keys and database credentials. Winter CMS administrators and security teams should assess exposure and prioritize remediation based on the severity of potential impacts.
- Vendor
- wintercms
- Product
- winter
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-10-08
Who should care
Winter CMS administrators and security teams should assess exposure and prioritize remediation based on the severity of potential impacts. Security teams should review compensating controls for exposed systems while remediation is scheduled and verified. Operators of affected systems should monitor for suspicious activity on the combine route and track exceptions, retest remediated assets, and close the item only after evidence is documented.
Why it matters
Winter CMS before 1.2.13 is vulnerable to local file inclusion via JavaScript, allowing authenticated users to disclose arbitrary server-readable files. This can lead to exposure of sensitive information such as application keys and database credentials.
- Authenticated users with cms.manage_assets permission can disclose arbitrary server-readable files
- Exposed application keys and database credentials can be read by unauthenticated visitors
Technical summary
The vulnerability is caused by a lack of proper input validation in the JavascriptImporter filter, which allows authenticated users to disclose arbitrary server-readable files. This can lead to exposure of sensitive information such as application keys and database credentials. The vulnerability has been patched in Winter CMS version 1.2.13. Defenders should prioritize remediation based on the severity of potential impacts and review compensating controls for exposed systems while remediation is scheduled and verified.
Defensive priority
Medium priority for Winter CMS administrators and security teams
Recommended defensive actions
- Update Winter CMS to version 1.2.13 or later
- Restrict access to the cms.manage_assets permission
- Monitor for suspicious activity on the combine route
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is described in the CVE Program record and the NVD vulnerability detail page. The Winter CMS project has released patches for the vulnerability. Evidence is limited to public CVE details and vendor advisories. Defenders should verify patch deployment and monitor for suspicious activity on the combine route. No exploit details are publicly available.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-79773 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-79773
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-79773 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79773
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Winter CMS before 1.2.13 Local File Inclusion via JavaScript
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/79xxx/CVE-2026-79773.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/wintercms/winter/security/advisories/GHSA-2223-f22x-24cq
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/wintercms/winter/commit/e09c8d3526f3583cb6c3476a021b885088ecd4bd
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/wintercms/storm/commit/fd673f4f32140c97c68b1ed705764b819747fbdf
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/winter-cms-before-local-file-inclusion-via-javascript
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.