Sceawere

Vulnerability Detail

CVE-2026-105329UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TallCMS Remote Code Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
3h ago
Vendor
n/a
Product
TallCMS
Attack Type
Code Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in TallCMS up to 4.8.0. This affects an unknown function of the file packages/tallcms/cms/src/Filament/Pages/ThemeManager.php of the component PluginManager. Executing a manipulation can lead to code injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called fdc18f4c6a36134f8986ca1d7e4e97092e3deb93. It is best practice to apply a patch to resolve this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-05T16:17:12.460Z",
  "pubdate": "2026-10-05T16:17:12.460Z",
  "executiveSummary": "TallCMS versions up to 4.8.0 are susceptible to a critical remote code injection vulnerability located within the PluginManager component.\nThis vulnerability allows unauthenticated or remote attackers to inject and execute arbitrary code on the underlying server, potentially leading to a complete compromise of the application and server environment.\nThe flaw resides specifically in the ThemeManager.php file, which fails to adequately sanitize or validate user-supplied input before processing it.\nGiven that the exploit details have been publicly disclosed, the risk profile is significantly elevated, making immediate remediation essential for affected installations.\nAttackers can leverage this vulnerability to gain unauthorized control, access sensitive data, or perform lateral movement within the hosting infrastructure.\nFailure to patch this vulnerability exposes the system to trivial remote exploitation, necessitating an immediate transition to a patched version or application of the provided security update.",
  "technicalDetails": "The vulnerability is a Remote Code Injection flaw situated in packages/tallcms/cms/src/Filament/Pages/ThemeManager.php within the PluginManager component of TallCMS.\nThe root cause of this vulnerability is the insecure handling of user-controlled input that is subsequently passed into dangerous functions or evaluation contexts within the ThemeManager lifecycle.\nBy manipulating specific parameters processed by the ThemeManager, an attacker can influence the execution flow to introduce malicious PHP code.\nThe attack flow begins with the attacker identifying the entry point within the Filament-based page controller. By crafting a malicious payload, the attacker sends an HTTP request targeting the vulnerable PluginManager logic.\nBecause the input validation mechanisms in versions up to 4.8.0 are insufficient, the application fails to distinguish between legitimate configuration data and executable code.\nOnce the payload reaches the server-side, it is interpreted or executed by the application runtime. This effectively bypasses intended functional constraints, leading to the execution of arbitrary commands with the privileges of the web server process.\nThis type of vulnerability is particularly severe in the context of PHP-based frameworks, as it allows for the invocation of system-level functions like shell_exec, system, or passthru, depending on the server configuration and the specific implementation within the vulnerable file.\nPost-exploitation impact includes full system compromise, exfiltration of configuration files containing database credentials, or the deployment of persistent backdoors to maintain long-term access.\nThe flaw is network-accessible, meaning that no local physical access is required. The lack of stringent input filtering or sandboxing for the plugin management interface creates a high-impact vector for remote attackers.\nThe technical mechanism requires the attacker to bypass any existing middleware or authentication layers if they are not correctly implemented at the route level for the ThemeManager page; however, the core flaw remains the lack of sanitization within the component logic itself.\nExploitation is facilitated by the public disclosure of the exploit, allowing threat actors to identify and weaponize the specific parameters handled by the PluginManager with minimal effort."
}
CVE-2026-105329: TallCMS Remote Code Injection Vulnerability (MEDIUM Severity, CVSS: 6.3) | Sceawere