OS Command Injection in baserCMS Website Development Framework
CVE-2026-21861

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-21861?

The baserCMS framework, prior to version 5.2.3, is susceptible to an OS command injection vulnerability occurring in the core update functionality. This flaw arises from inadequate validation and escaping of user-controlled input, which permits authenticated administrators to execute arbitrary OS commands on the server. Attackers could exploit this issue, potentially compromising the security of the server hosting the baserCMS application. A patch addressing this vulnerability was released in version 5.2.3.

Affected Version(s)

basercms < 5.2.3

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.