CVE-2026-105226
Received Received - Intake

Code Injection in osCommerce Newsletter Management

Vulnerability report for CVE-2026-105226, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulDB

Description

A security flaw has been discovered in osCommerce osCommerce2 up to 2.3.4.1. This vulnerability affects the function include of the file admin/newsletters.php of the component Newsletter Management. Performing a manipulation of the argument module results in code injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
oscommerce oscommerce2 to 2.3.4.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored Remote Code Execution (RCE) flaw in osCommerce version 2.3.4.1. It exists in the Newsletter Management feature due to improper validation of the 'module' field, which is used both as a PHP class name and in file-include paths. Attackers can exploit this to write arbitrary files and execute malicious PHP code on the server.

Detection Guidance

Check for unauthorized PHP files in writable directories, especially those with 0777 permissions. Inspect admin/newsletters.php for suspicious module parameter values like 'upload' or path traversal sequences such as '../'. Review web server access logs for repeated POST requests to newsletter-related endpoints.

Impact Analysis

An authenticated admin attacker can exploit this to fully compromise the server. This allows reading/writing any reachable files, executing arbitrary code as the web server user, and potentially moving laterally within the network. The attack requires minimal interaction due to lack of CSRF protection.

Compliance Impact

This vulnerability allows arbitrary PHP code execution on the server, which could lead to unauthorized access to sensitive data. For GDPR, this may result in a data breach requiring notification under Article 33. For HIPAA, it could expose protected health information, violating the Security Rule. Both standards mandate safeguards against such exploits.

Mitigation Strategies

Upgrade osCommerce to a patched version if available. Restrict write permissions on directories to prevent arbitrary file uploads. Implement server-side allow-lists for valid 'module' values. Disable CSRF protection bypasses and monitor for unauthorized admin actions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105226. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart