Skip to content
CVE-2026-105123: Remote Code Execution in vincent-peugnet/wcms

CVE-2026-105123: Remote Code Execution in vincent-peugnet/wcms

First seen 5 Oct 2026, 02:03 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 03:03 UTC
  • •CVE-2026-105123 allows remote code execution in vincent-peugnet/wcms.
  • •Authenticated editors can exploit the upload API to upload malicious files.
  • •Immediate patching is recommended to mitigate high operational risks.

A remote code execution vulnerability, CVE-2026-105123, has been identified in vincent-peugnet/wcms versions up to 3.18.0. This flaw allows authenticated editors to upload arbitrary files, including .php files, by exploiting an unvalidated path in the upload API. Attackers can also use encoded ../ sequences to write outside the media directory and delete files via a specific DELETE request. The risk is particularly high for internet-facing CMS instances with editor accounts, especially those with multiple contributors. The exploitation status remains unconfirmed, and no proof-of-concept (PoC) or exploitation in the wild has been reported yet. Administrators are urged to review upload API logs and restrict access to trusted networks. The vendor has released a fix, and immediate application is recommended to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-03
CVE-2026-105123 published
CVE-2026-105123 was added to the CVE List, detailing a remote code execution vulnerability in vincent-peugnet/wcms.
Nvd.Nist
Recent
Patch released
The vendor has issued a fix for the vulnerability in vincent-peugnet/wcms, urging immediate application.
Redpacketsecurity

More articles in this cluster (4)

Following this threat?

Track CVE-2026-105123 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
vincent-peugnet/wcms versions up to 3.18.0 are affected by CVE-2026-105123.
Is there any active exploitation?
No active exploitation has been confirmed, and the status remains unverified.
What should I do to protect my system?
Apply the vendor's patch immediately and review access controls for editor accounts.