Remote Code Execution in Vvveb CMS Media Management Functionality
CVE-2026-6257
9.2CRITICAL
What is CVE-2026-6257?
Vvveb CMS v1.0.8 has a vulnerability within its media management feature that allows authenticated attackers to exploit a missing return statement in the rename handler. This flaw enables attackers to rename files to restricted extensions such as .php or .htaccess. By first uploading a text file and renaming it to .htaccess, attackers can inject Apache directives to register PHP-executable MIME types. Subsequently, they can upload another file and rename it to .php, leading to the execution of arbitrary commands on the server as the www-data user, which poses significant security risks.
Affected Version(s)
Vvveb CMS 1.0.8
