Code Injection Vulnerability in osCommerce Newsletter Management Module
CVE-2026-105226
Key Information:
- Vendor
Oscommerce
- Status
- Vendor
- CVE Published:
- 5 October 2026
Badges
What is CVE-2026-105226?
A code injection vulnerability has been identified in the Newsletter Management module of osCommerce versions up to 2.3.4.1. This security flaw resides in the 'include' function within the admin/newsletters.php file. By manipulating the argument module, an attacker can potentially execute remote code, allowing unauthorized commands to be run on the server. The exploit has been publicly disclosed, and while the osCommerce project was alerted to this issue through an issue report, no response has been documented. Users are advised to review their systems for this vulnerability to prevent potential exploitation.
Affected Version(s)
osCommerce2 2.3.4.0
osCommerce2 2.3.4.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
