CVE-2026-95501: Code Injection in mtrano APENCMS
CVE-2026-95501 is a medium severity code injection vulnerability in mtrano APENCMS affecting the Template Engine component. The vulnerability arises from unsafe use of the eval function in cms/weasel.php, where manipulation of the $_CMS['site'] argument allows remote code injection. The product uses a rolling release system, so specific affected or fixed versions are not disclosed. The vendor did not respond to early disclosure attempts. Exploit code has been publicly released but no known exploitation in the wild is reported.
AI Analysis
Technical Summary
This vulnerability in mtrano APENCMS up to commit 6546096d354153309693efabb9a0d824628ed4f5 involves the eval function in cms/weasel.php within the Template Engine component. An attacker can manipulate the $_CMS['site'] argument to inject and execute arbitrary code remotely. The product's rolling release model means no explicit versioning information is available for affected or patched releases. The vendor was contacted but did not provide any response or advisory. Public exploit code exists, increasing the risk of potential exploitation.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary code on the affected system with high privileges, potentially compromising the integrity and confidentiality of the CMS environment. The CVSS 4.0 base score is 4.8 (medium), reflecting network attack vector, low complexity, no privileges required for attack initiation, but requiring high privileges and partial user interaction. The impact on confidentiality, integrity, and availability is low to limited.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded and no official fix is disclosed, users should monitor for updates from the vendor or community. Until a fix is available, avoid exposing the vulnerable component to untrusted networks or inputs that can manipulate $_CMS['site'].
CVE-2026-95501: Code Injection in mtrano APENCMS
Description
CVE-2026-95501 is a medium severity code injection vulnerability in mtrano APENCMS affecting the Template Engine component. The vulnerability arises from unsafe use of the eval function in cms/weasel.php, where manipulation of the $_CMS['site'] argument allows remote code injection. The product uses a rolling release system, so specific affected or fixed versions are not disclosed. The vendor did not respond to early disclosure attempts. Exploit code has been publicly released but no known exploitation in the wild is reported.
CVSS v4.0
Score 4.8medium
Affected software
mtrano
APENCMS
cpe:2.3:a:mtrano:apencms:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in mtrano APENCMS up to commit 6546096d354153309693efabb9a0d824628ed4f5 involves the eval function in cms/weasel.php within the Template Engine component. An attacker can manipulate the $_CMS['site'] argument to inject and execute arbitrary code remotely. The product's rolling release model means no explicit versioning information is available for affected or patched releases. The vendor was contacted but did not provide any response or advisory. Public exploit code exists, increasing the risk of potential exploitation.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary code on the affected system with high privileges, potentially compromising the integrity and confidentiality of the CMS environment. The CVSS 4.0 base score is 4.8 (medium), reflecting network attack vector, low complexity, no privileges required for attack initiation, but requiring high privileges and partial user interaction. The impact on confidentiality, integrity, and availability is low to limited.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded and no official fix is disclosed, users should monitor for updates from the vendor or community. Until a fix is available, avoid exposing the vulnerable component to untrusted networks or inputs that can manipulate $_CMS['site'].
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-22T06:31:10.568Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab29537f7a7c541064ee1b0
Added to database: 09/22/2026, 14:48:23 UTC
Last enriched: 09/22/2026, 15:02:38 UTC
Last updated: 09/22/2026, 15:07:36 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.