PT-2026-95007 · Cakephp+1 · Cakephp+1

·

CVE-2026-93295

·

Published

2026-09-17

·

Updated

2026-09-22

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MISP (affected versions not specified)
Description A flaw in the background job dispatch mechanism allows remote code execution with the privileges of the web user. The issue occurs because background job arguments are passed directly as the argv of the CakePHP console process. The ShellDispatcher:: parsePaths() function scans argv for path switches such as -app, --app, -working, --working, -root, --root, -webroot, and --webroot, using the subsequent element as the application root. Specifically, the 'events/contact' endpoint forwards the message and person fields into job arguments without validation. An attacker can set the person field to a reserved switch and the message field to a phar:// URI (a PHP archive wrapper) pointing to a malicious archive. This causes the CakePHP bootstrap to include Config/core.php from the archive, executing arbitrary PHP code. This allows for data exfiltration, persistence, and lateral movement within the host.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93295

Affected Products

Cakephp
Misp