CVE-2026-29014
PoC ×2largeUnauthenticated PHP Code Injection RCE in MetInfo CMS
CVE-2026-29014 is an unauthenticated PHP code injection flaw (CWE-94) in MetInfo CMS, caused by insufficient neutralization of user-supplied input in an execution path that evaluates PHP. A remote attacker needs no privileges or user interaction and triggers the flaw simply by sending crafted requests containing malicious PHP, which the server then executes. Successful exploitation results in full remote code execution, giving the attacker complete control over the affected web server and everything it hosts. All MetInfo CMS 7.9, 8.0, and 8.1 deployments are affected, with risk concentrated in internet-facing installations. Exploitation has been reported in the wild, public PoCs are available, and the 39.5% EPSS score (99th percentile) signals high near-term exploitation risk, though the flaw is not yet listed in CISA KEV.
What to do: Upgrade MetInfo CMS to the latest patched release; the advisory flags 7.9, 8.0, and 8.1 as affected, so confirm the exact fixed version in the vendor's advisory before upgrading, and prioritize internet-facing instances. Until patched, restrict or WAF-filter HTTP access to MetInfo endpoints and review access logs for crafted requests containing injected PHP syntax. Use the public PoC write-ups (Karmain Security KIS-2026-06 and WebSec) to identify the vulnerable request pattern when hunting for signs of compromise.
| metinfo | 7.9, 8.0, 8.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.
- Vendors
- metinfo
- Products
- metinfo
- Weakness
- CWE-94
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X