SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-45139

MEDIUM · CVSS 6.5 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The Fileeditor module in CI4MS, prior to version 0.31.9.0, allows backend users with file-editor permissions to delete or rename any file in the project root without validating the file extension, bypassing the extension allowlist. This vulnerability can lead to the destruction of critical framework files, resulting in a persistent denial of service that necessitates filesystem-level recovery. Organizations using CI4MS should prioritize upgrading to version 0.31.9.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-45139
Severity
MEDIUM
CVSS
6.5
EPSS
0.27%

Original NVD Description

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on content-write operations (`saveFile`, `createFile`), but two destructive endpoints — `deleteFileOrFolder` and `renameFile` — never validate the extension of the *source* path. A backend user with file-editor permissions can therefore unlink or rename any file inside the project root that is not explicitly listed in the small `$hiddenItems` blocklist. Critical framework files such as `app/Config/Routes.php`, `app/Config/App.php`, `app/Config/Database.php`, `app/Config/Filters.php`, `public/index.php`, and `public/.htaccess` all live outside that blocklist and can be destroyed, producing a persistent denial of service that requires filesystem-level redeployment to recover. Version 0.31.9.0 patches the issue.