CVE-2026-79362
—CVSS
—
EPSS
—
Published
()
Modified
Description
Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until = 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code.
In the news0 stories
No ingested article mentions this CVE yet.