PT-2026-87192 · Git+1 · Icms2

CVE-2026-54611

·

Published

2026-09-08

·

Updated

2026-09-08

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix.

Exploit

Fix

Unrestricted File Upload

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54611
GHSA-VVGV-H28H-P2M5

Affected Products

Icms2