Remote Code Execution Vulnerability in InstantCMS by InstantSoft
CVE-2026-54611
5.5MEDIUM
What is CVE-2026-54611?
InstantCMS, an open-source content management system, is susceptible to a Remote Code Execution vulnerability affecting versions prior to 2.18.2. This flaw enables remote authenticated attackers to execute arbitrary PHP code through a misconfigured component installer. Attackers can upload a malicious component, and while it won't be directly installed, they can manipulate the server to execute files. By uploading a custom .htaccess file, the usual restrictions on PHP file execution in the upload directory can be bypassed, potentially exposing the server to serious security risks. Version 2.18.2 addresses this vulnerability with the necessary fixes.
Affected Version(s)
icms2 < 2.18.2
