Sceawere
Vulnerability Detail
CVE-2026-105123UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
W CMS Arbitrary File Write RCE
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- vincent-peugnet
- Product
- wcms
- Attack Type
- Unrestricted Upload of File with Dangerous Type
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path].
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-04T00:16:35.703Z",
"pubdate": "2026-10-04T00:16:35.703Z",
"executiveSummary": "W (vincent-peugnet/wcms) versions through 3.18.0 are susceptible to a critical Remote Code Execution (RCE) vulnerability stemming from improper input validation in the media management API.\nThe vulnerability allows an authenticated user with editor-level privileges to perform unauthorized file system operations, including arbitrary file uploads and deletions.\nBy manipulating the path parameter in the /api/v0/media/upload/ and /api/v0/media/ endpoints, an attacker can bypass intended directory restrictions using path traversal sequences.\nSuccessful exploitation enables the placement of executable .php files in arbitrary locations, facilitating complete server-side code execution.\nThe risk is categorized as high, as it grants attackers the ability to compromise the integrity and availability of the underlying web server through malicious file placement and unauthorized data removal.\nExploitation requires active authentication as an editor, limiting the attack surface to malicious insiders or compromised editorial accounts.",
"technicalDetails": "The root cause of this vulnerability is the lack of server-side sanitization and validation of the path variable within the API routes handling media management. Specifically, the endpoints POST /api/v0/media/upload/[*:path] and DELETE /api/v0/media/[*:path] do not adequately restrict the scope of file system operations to the designated media directory.\nThe application fails to resolve or filter directory traversal sequences (e.g., ../) provided within the [*:path] parameter. This failure allows an attacker to escape the intended directory sandbox and interact with any location on the file system that the web server process has write or delete permissions to.\nThe attack flow for remote code execution proceeds as follows: 1. An authenticated attacker acting with the privileges of an editor initiates a POST request to /api/v0/media/upload/ targeting a directory outside the media root by injecting encoded path traversal sequences (e.g., ../../web/shell.php). 2. The server processes the request and saves the uploaded payload, which can be crafted as a valid PHP script, into the specified arbitrary directory. 3. The attacker then triggers the execution of the uploaded script by requesting the file path directly via the web server. 4. Due to the server's configuration to process PHP files, the payload is executed, granting the attacker arbitrary command execution.\nIn addition to arbitrary file writing, the DELETE /api/v0/media/[*:path] endpoint allows for arbitrary file deletion. By manipulating the [*:path] variable, an attacker can cause the application to remove critical system files, application configuration files, or other sensitive data, leading to a denial-of-service condition or further system instability.\nThe vulnerable component is the media API logic which handles path input for file system operations without performing canonicalization or white-listing of permitted directory structures. The vulnerability persists in all versions of vincent-peugnet/wcms up to and including 3.18.0, requiring developers to implement strict path validation or utilize secure file handling libraries that prevent directory traversal."
}