Description
A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown functionality of the file /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html of the component Template Handler. Performing a manipulation results in os command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: 2.2% Low
KEV: No
Impact: OS Command Injection
Action: Assess Impact
AI Analysis

Impact

The vulnerability exists in the MacCMS10 Template Handler endpoint, specifically in the handling of the path /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html. The flaw allows an attacker to supply a crafted path that is not properly sanitized, resulting in an operating‑system command being executed. The CVE description confirms remote initiation of the attack and indicates that the exploit has been publicized, implying that an attacker could potentially execute arbitrary commands on the affected server.

Affected Systems

Infections are limited to installations of magicblack MacCMS10 version 2026.1000.4055 that expose the /admin1.php/admin/template/index/path/ endpoint. Any site running this component and allowing public access to the endpoint is potentially vulnerable, while installations without this endpoint or those that restrict access remain unaffected.

Risk and Exploitability

The CVSS score of 5.1 indicates a medium severity. The EPSS score of 1.57% signals that exploitation is unlikely yet not impossible, and the vulnerability is not listed in the CISA KEV catalog. An attacker can send a crafted request to the vulnerable endpoint, triggering an OS command injection. Public exploit code has been released, so exposed systems face a significant risk if the flaw is not mitigated.

Generated by OpenCVE AI on September 21, 2026 at 02:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check for an available patch or update from the vendor and apply it as soon as it becomes available, which will correct the vulnerable path handling.
  • If no patch is available, restrict access to the /admin1.php endpoint to trusted users only, limiting the attack surface.
  • Configure a web application firewall or reverse‑proxy rule to detect and block requests containing malicious path traversal patterns, preventing the malicious payload from reaching the backend.

Generated by OpenCVE AI on September 21, 2026 at 02:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown functionality of the file /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html of the component Template Handler. Performing a manipulation results in os command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title magicblack MacCMS10 Template .%40template%40default%40html%40label.html os command injection
First Time appeared Magicblack
Magicblack maccms10
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:magicblack:maccms10:*:*:*:*:*:*:*:*
Vendors & Products Magicblack
Magicblack maccms10
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Magicblack Maccms10
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T15:05:33.080Z

Reserved: 2026-09-13T13:12:14.654Z

Link: CVE-2026-90788

cve-icon Vulnrichment

Updated: 2026-09-16T15:05:28.177Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T14:17:19.707

Modified: 2026-09-16T16:17:20.710

Link: CVE-2026-90788

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T08:15:16Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')