Back

CRITICAL

MetInfo CMS Unauthenticated PHP Code Injection RCE

Published Apr 1, 2026

Description

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 1, 2026
Updated Jul 14, 2026
Reserved Mar 3, 2026
CISA Vulnrichment
Updated Apr 3, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Apr 1, 2026
Updated Jul 14, 2026
Exploited since n/a
EUVD-2026-17875