PT-2026-29514 · Unknown · Metinfo Cms

Egidio Romano

·

Published

2026-04-01

·

Updated

2026-05-06

·

CVE-2026-29014

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MetInfo CMS versions 7.9 through 8.1
Description An unauthenticated PHP code injection flaw allows remote attackers to execute arbitrary code by sending crafted requests containing malicious PHP code. This issue stems from insufficient input neutralization in the execution path, enabling attackers to achieve remote code execution and gain full control over the affected server. Real-world exploitation has been observed since April 25, with a significant increase in activity starting May 1. Attackers have used this flaw to gain initial access, escalate privileges, and move laterally across networks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-29014

Affected Products

Metinfo Cms