CVE-2026-29014 CRITICAL

CVE-2026-29014: MetInfo CMS Unauthenticated PHP Code Injection RCE

Vendor Metinfo Cms
Product MetInfo CMS
Weakness CWE-94 · Code injection
Published April 1, 2026
Last update April 3, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

Description

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.

Key dates

Disclosure timeline

April 1, 2026 CVE published
April 3, 2026 Record updated