OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-97150

HIGH · CVSS 7.2 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The BcAddonMigrator tool in baserCMS5 improperly includes the "config.php" file from baserCMS4-style addons, allowing for the execution of arbitrary PHP code. This vulnerability can lead to unauthorized reading or deletion of files on the system by an administrative user. Organizations using baserCMS should prioritize patching this issue to mitigate potential risks associated with administrative access exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-97150
Severity
HIGH
CVSS
7.2
EPSS
0.34%

Original NVD Description

When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.