
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3714 is a template injection vulnerability in OpenCart 4.0.2.3, specifically affecting the Save function in admin/controller/design/template.php. It represents an incomplete fix for the previously disclosed CVE-2024-36694, allowing improper neutralization of special elements used in a template engine. The vulnerability was disclosed on March 8, 2026, and the vendor did not respond to early contact. It carries a CVSS v3.1 base score of 4.7 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (Red Hat CVE, VulDB).
The root cause is classified under CWE-791 (Incomplete Filtering of Special Elements) and CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine). The prior patch for CVE-2024-36694 failed to fully sanitize user-supplied input processed by the template engine in the admin panel's design/template controller. An authenticated attacker with high-privilege (admin-level) access can remotely manipulate template content to inject special elements that are interpreted by the template engine, potentially leading to server-side template injection (SSTI). The attack requires no user interaction and is performed over the network (VulDB, ENISA EUVD).
Successful exploitation can result in limited confidentiality, integrity, and availability impacts on the affected OpenCart instance, as reflected in the CVSS scoring (low impact across all three dimensions). An attacker with admin credentials could manipulate template files, potentially reading sensitive configuration data, altering storefront content, or causing minor service disruption. The scope is limited to the affected system and does not extend to other systems, reducing lateral movement risk (VulDB, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been confirmed for CVE-2026-3714 as of the latest available data. The EPSS score is approximately 0.053%, indicating a low probability of exploitation in the near term. Exploitation requires high-privilege (administrator-level) authentication, significantly limiting the attack surface. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (VulDB, ENISA EUVD).
admin/controller/design/template.php./admin/index.php?route=design/template or similar template-related admin endpoints containing template engine syntax (e.g., {%, {{, {$, or similar delimiters) in request bodies..twig, .php) in the OpenCart catalog/view/theme/ or admin/view/template/ directories with recently changed timestamps.No official vendor patch has been released for CVE-2026-3714, as OpenCart did not respond to the researcher's disclosure. As a workaround, administrators should restrict access to the OpenCart admin panel to trusted IP addresses using firewall rules or web server access controls. Enforcing strong, unique credentials for admin accounts and enabling multi-factor authentication (if supported) reduces the risk of unauthorized access. Organizations should monitor for a future patch release from OpenCart and apply it promptly upon availability (VulDB, Red Hat CVE).
The vulnerability was assigned by VulDB and has been tracked by ENISA under EUVD-2026-10220. Coverage has been limited to automated vulnerability tracking platforms and aggregators such as CVEFeed, CIRCL, and INCIBE-CERT, with no notable researcher commentary or significant social media discussion identified. The vendor's lack of response to the disclosure has been noted in the advisory (VulDB, ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."