CVE-2026-67595

8.1

WebReinvent · VaahCMS

VaahCMS versions 2.0.0 through 2.3.4 contain embedded malicious code, posing a supply chain risk.

Executive summary

VaahCMS versions 2.0.0 through 2.3.4 are affected by a supply chain vulnerability involving embedded malicious code that could lead to full system compromise.

Vulnerability

This vulnerability involves the presence of embedded malicious code (CWE-506) within the application, which allows for remote code execution. The attack vector is network-based and does not require authentication, making it a critical threat to the application integrity.

Business impact

Successful exploitation allows an attacker to gain full control over the application, leading to total compromise of confidentiality, integrity, and availability. With a CVSS score of 8.1, the potential for unauthorized data exfiltration or site defacement is high, posing severe reputational and operational risks to the business.

Remediation

Immediate Action: Upgrade to the latest version or apply the specific security fix provided in the referenced commit (8d7898f7a385a5fade1180a9b664ff158d873129).

Proactive Monitoring: Review web application logs for suspicious outbound traffic or unauthorized file modifications that might indicate malicious code execution.

Compensating Controls: Deploy a Web Application Firewall (WAF) to filter malicious payloads and restrict access to administrative endpoints.

Exploitation status

Public Exploit Available: No confirmed public exploit.

Analyst recommendation

Due to the nature of this vulnerability involving embedded malicious code, immediate remediation is required. Administrators must verify their VaahCMS version and apply the vendor-supplied fix to ensure the removal of the compromised components and restore the security of the application environment.

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Fix documented per CVE record