Description
Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code.
Published: 2026-09-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

Certain versions of WoltLab Suite Core are vulnerable to remote code execution through cache poisoning. An authenticated low‑privileged user can inject arbitrary PHP code into cache files that the application later executes. Attacker‑controlled data can prematurely terminate the nowdoc syntax, allowing malicious PHP to be written into executable cache files. Once these files are processed, the injected code runs with the privileges of the web server process, giving the attacker the ability to perform actions that the web server would normally permit.

Affected Systems

WoltLab Suite Core versions 6.1.0 through 6.1.22 and 6.2.0 through 6.2.5 are affected. The vulnerability exists in installations running WCF from 6.1.0 up to, but not including, 6.1.23, and from 6.2.0 up to, but not including, 6.2.6. Only systems that have not been upgraded to at least 6.1.23 or 6.2.6 are susceptible.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1 % shows a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector requires authenticated low‑privileged user access, making random attacks less likely, but successful exploitation results in uncompromised code execution on the server. Based on the description, it is inferred that the attacker would need to submit specially crafted data that terminates the nowdoc prematurely; once achieved, malicious PHP code would run with web‑server privileges.

Generated by OpenCVE AI on September 21, 2026 at 19:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WoltLab Suite Core to version 6.1.23 or later, or 6.2.6 or later, to remove the vulnerable cache‑poisoning logic.
  • If an upgrade cannot be performed immediately, restrict user input that influences cache generation by limiting the privileges of low‑privileged users or disabling cached content for them.
  • Configure the web server to disallow PHP execution in the directory where WoltLab writes cache files, preventing any injected code from running even if cache contains unexpected PHP code.

Generated by OpenCVE AI on September 21, 2026 at 19:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Cache Poisoning in WoltLab Suite

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Cache Poisoning in WoltLab Suite
Weaknesses CWE-94

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Woltlab
Woltlab wcf
Vendors & Products Woltlab
Woltlab wcf

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-21T16:01:59.505Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79362

cve-icon Vulnrichment

Updated: 2026-09-21T16:00:15.343Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T19:17:45.940

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-79362

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:15:18Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')