CVE-2026-79362

high

Description

Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code.

References

https://www.woltlab.com/community/thread/319264-aktualisierung-woltlab-suite-6-2-6-6-1-23/

https://www.woltlab.com/community/thread/319263-update-woltlab-suite-6-2-6-6-1-23/

https://github.com/WoltLab/WCF/commit/c19789dbcc15663c648db1b196b6e6b05265b121

Details

Source: Mitre, NVD

Published: 2026-09-11

Updated: 2026-09-22

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00166