Remote Code Execution Vulnerability in InstantCMS by InstantSoft
CVE-2026-54611

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-54611?

InstantCMS, an open-source content management system, is susceptible to a Remote Code Execution vulnerability affecting versions prior to 2.18.2. This flaw enables remote authenticated attackers to execute arbitrary PHP code through a misconfigured component installer. Attackers can upload a malicious component, and while it won't be directly installed, they can manipulate the server to execute files. By uploading a custom .htaccess file, the usual restrictions on PHP file execution in the upload directory can be bypassed, potentially exposing the server to serious security risks. Version 2.18.2 addresses this vulnerability with the necessary fixes.

Affected Version(s)

icms2 < 2.18.2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.