Sceawere
Vulnerability Detail
CVE-2026-94389UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AcyMailing SMTP RCE Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9
- Creation Date
- 3h ago
- Vendor
- AcyMailing Newsletter Team
- Product
- AcyMailing SMTP Newsletter
- Attack Type
- CWE-94 Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.0",
"pubDate": "2026-09-30T13:17:26.840Z",
"pubdate": "2026-09-30T13:17:26.840Z",
"executiveSummary": "The AcyMailing SMTP Newsletter plugin for CMS platforms, specifically versions 11.0.5 and below, contains a critical security vulnerability that allows for unauthenticated Remote Code Execution (RCE).\nThis vulnerability exists due to improper input sanitization and insecure handling of user-supplied data within the SMTP processing or newsletter configuration components.\nAn unauthenticated, remote attacker can leverage this flaw to inject malicious commands that are executed directly by the underlying server operating system with the privileges of the web application user.\nThe impact of this vulnerability is severe, potentially resulting in full system compromise, sensitive data exfiltration, unauthorized administrative access, and lateral movement within the network infrastructure.\nNo authentication is required for exploitation, significantly lowering the barrier for entry for threat actors.\nGiven the nature of RCE, this is considered a critical risk requiring immediate remediation to prevent widespread exploitation and compromise of the host environment.",
"technicalDetails": "The vulnerability resides within the AcyMailing SMTP Newsletter plugin, specifically affecting versions 11.0.5 and earlier. The root cause is categorized as an injection flaw, likely manifesting as improper sanitization of parameters handled during SMTP configuration or the newsletter delivery pipeline.\nThe attack flow initiates when an unauthenticated actor sends a crafted HTTP request to the vulnerable endpoint responsible for processing SMTP settings or newsletter operations. Because the input parameters are not adequately validated or escaped before being processed by the application's backend logic, an attacker can inject malicious code—often formatted as shell commands or system execution payloads—into the parameters.\nUpon reaching the vulnerable component, the malicious payload is passed to a backend function that improperly executes the input, potentially through unsafe calls to PHP system execution functions such as 'system()', 'exec()', or 'passthru()'. This allows the attacker to hijack the execution flow of the script.\nThe exploitation process typically follows these steps: 1) Identification of the target endpoint that handles SMTP or newsletter parameters without authentication. 2) Crafting a payload designed to bypass existing sanitization mechanisms, potentially utilizing command injection vectors. 3) Delivering the payload via a standard HTTP request (e.g., GET or POST). 4) Triggering the backend execution of the malicious commands.\nPost-exploitation, the attacker gains the ability to execute arbitrary commands with the privilege level of the web server (e.g., 'www-data'). This level of access grants the capability to establish reverse shells for persistent access, dump database contents containing user information, install malicious web shells, or utilize the server as a pivot point for attacking other internal network assets.\nThe vulnerability is critical because it bypasses standard authentication controls, meaning any internet-facing instance of the vulnerable plugin is exposed to remote command execution without requiring any prior knowledge or valid credentials from the system."
}