Remote Code Execution in Vvveb CMS Media Management Functionality
CVE-2026-6257

9.2CRITICAL

Key Information:

Vendor

Vvveb

Status
Vendor
CVE Published:
20 April 2026

What is CVE-2026-6257?

Vvveb CMS v1.0.8 has a vulnerability within its media management feature that allows authenticated attackers to exploit a missing return statement in the rename handler. This flaw enables attackers to rename files to restricted extensions such as .php or .htaccess. By first uploading a text file and renaming it to .htaccess, attackers can inject Apache directives to register PHP-executable MIME types. Subsequently, they can upload another file and rename it to .php, leading to the execution of arbitrary commands on the server as the www-data user, which poses significant security risks.

Affected Version(s)

Vvveb CMS 1.0.8

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mohammed EL OUARDANI
.