CVE-2026-79362
Received Received - Intake

Remote Code Execution in WoltLab Suite Core via Cache Poisoning

Vulnerability report for CVE-2026-79362, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: MITRE

Description

Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
woltlab wcf From 6.1.0 (inc) to 6.1.23 (exc)
woltlab wcf From 6.2.0 (inc) to 6.2.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-79362 is an authenticated Remote Code Execution (RCE) vulnerability in WoltLab Suite Core affecting versions 6.1.0 to 6.1.22 and 6.2.0 to 6.2.5. An authenticated low-privileged user can inject PHP code into cache files by terminating the nowdoc prematurely. This allows arbitrary code execution on the server.

Detection Guidance

Check WoltLab Suite versions for affected releases (6.1.0 to <6.1.23 and 6.2.0 to <6.2.6). Inspect cache files for unusual PHP code or unexpected .v2.php files. Use server logs to identify unauthorized cache file modifications or suspicious user activity.

Impact Analysis

This vulnerability allows attackers with low privileges to execute arbitrary code on the server. This could lead to full system compromise, data theft, unauthorized access, or disruption of services. All versions before 6.1.23 and 6.2.6 are affected.

Mitigation Strategies

Update WoltLab Suite to versions 6.1.23 or 6.2.6 or later immediately. Flush all cache files to remove potentially compromised versions. Ensure the update is applied via the Administration Control Panel by checking for updates in the package list.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79362. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart