High severity7.3NVD Advisory· Published Sep 16, 2026
CVE-2026-92718
CVE-2026-92718
Description
Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modification time to bypass signature checks and execute arbitrary operating system commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.11.1
Patches
Vulnerability mechanics
References
5- github.com/projectdiscovery/nuclei/blob/v3.11.0/pkg/catalog/index/metadata.gonvd
- github.com/projectdiscovery/nuclei/blob/v3.11.0/pkg/templates/compile.gonvd
- github.com/projectdiscovery/nuclei/commit/9de96e4dda5a03da963b9ae6582f03ea55791a76nvd
- github.com/projectdiscovery/nuclei/issues/7663nvd
- www.vulncheck.com/advisories/nuclei-from-3.7.0-before-3.11.1-template-signature-bypass-via-modification-time-only-cachenvd
News mentions
0No linked articles in our index yet.