PT-2026-27219 · Unknown+1 · Connect-Cms+1

Odgrso

·

Published

2026-03-23

·

Updated

2026-03-24

·

CVE-2026-32276

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Connect-CMS versions prior to 1.41.1 Connect-CMS versions prior to 2.41.1
Description Connect-CMS is a content management system. An authenticated user may be able to execute arbitrary code in the Code Study Plugin. If exploited, this could lead to code execution on the server or information disclosure.
Recommendations Update Connect-CMS to version 1.41.1 or later. Update Connect-CMS to version 2.41.1 or later.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-32276
GHSA-HXQW-6QV7-CQFV

Affected Products

Code Study Plugin
Connect-Cms