CVE-2026-97150
Received Received - Intake

Arbitrary File Read/Delete in baserCMS Addon Migrator

Vulnerability report for CVE-2026-97150, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: JPCERT/CC

Description

When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
baserproject bcaddonmigrator to 5.2.1 (exc)
baserproject bcaddonmigrator 5.2.1
baserproject bcaddonmigrator From 5.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the BcAddonMigrator plugin for baserCMS. When converting addons from baserCMS4 to baserCMS5 style, the system includes and executes a config.php file from the addon ZIP archive. This allows arbitrary PHP code execution with web server permissions during the conversion process.

Detection Guidance

Check if BcAddonMigrator version 5.2.0 or earlier is installed. Look for suspicious file reads or deletions in system logs during addon conversion processes. Review uploaded ZIP files for unexpected config.php files.

Impact Analysis

An attacker with administrative privileges could exploit this to read or delete arbitrary files on the system. They could also execute malicious PHP code on the server by uploading a specially crafted addon ZIP file.

Compliance Impact

This vulnerability could lead to unauthorized data access or deletion, potentially violating GDPR's data protection requirements or HIPAA's security rules for protected health information. Unauthorized code execution may also compromise system integrity.

Mitigation Strategies

Update BcAddonMigrator to version 5.2.1 or later immediately. If not in use, disable the plugin. Avoid processing ZIP files from untrusted sources during addon conversion.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97150. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart