Redpacketsecurity CVE-2026-105123: Remote Code Execution in vincent-peugnet/wcms
Article Content
- •CVE-2026-105123 allows remote code execution in vincent-peugnet/wcms.
- •Authenticated editors can exploit the upload API to upload malicious files.
- •Immediate patching is recommended to mitigate high operational risks.
A remote code execution vulnerability, CVE-2026-105123, has been identified in vincent-peugnet/wcms versions up to 3.18.0. This flaw allows authenticated editors to upload arbitrary files, including .php files, by exploiting an unvalidated path in the upload API. Attackers can also use encoded ../ sequences to write outside the media directory and delete files via a specific DELETE request. The risk is particularly high for internet-facing CMS instances with editor accounts, especially those with multiple contributors. The exploitation status remains unconfirmed, and no proof-of-concept (PoC) or exploitation in the wild has been reported yet. Administrators are urged to review upload API logs and restrict access to trusted networks. The vendor has released a fix, and immediate application is recommended to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-105123 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions are affected?
Is there any active exploitation?
What should I do to protect my system?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…