CVE-2026-92718

high

Description

Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modification time to bypass signature checks and execute arbitrary operating system commands.

References

https://www.vulncheck.com/advisories/nuclei-from-3.7.0-before-3.11.1-template-signature-bypass-via-modification-time-only-cache

https://github.com/projectdiscovery/nuclei/issues/7663

https://github.com/projectdiscovery/nuclei/commit/9de96e4dda5a03da963b9ae6582f03ea55791a76

https://github.com/projectdiscovery/nuclei/blob/v3.11.0/pkg/templates/compile.go#L610-L624

https://github.com/projectdiscovery/nuclei/blob/v3.11.0/pkg/catalog/index/metadata.go#L78-L84

https://github.com/projectdiscovery/nuclei

Details

Source: Mitre, NVD

Published: 2026-09-16

Updated: 2026-09-18

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.3

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Severity: High

CVSS v4

Base Score: 7

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00109