SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-55578

HIGH · CVSS 8.8 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Pheditor versions 2.0.1 to before 2.0.6 are vulnerable due to an incomplete character blocklist in the terminal feature, allowing authenticated users with terminal permissions to execute arbitrary OS commands via shell_exec(). This high-severity vulnerability can lead to unauthorized command execution, potentially compromising the web server. Organizations using affected versions should prioritize updating to version 2.0.6 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55578
Severity
HIGH
CVSS
8.8
EPSS
0.36%

Original NVD Description

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the terminal feature in Pheditor uses an incomplete character blocklist to sanitize user-supplied commands before passing them to shell_exec(). After the fix for GHSA-9643-6xjp-vx57 (which added $ to the blocklist), the characters | (single pipe), ` (backtick), and the newline byte (0x0A) remain unblocked. An authenticated user with the terminal permission (enabled by default) can leverage any of these to bypass the TERMINAL_COMMANDS allowlist and execute arbitrary OS commands as the web server user. This issue has been patched in version 2.0.6.