PatchSiren cyber security CVE debrief
CVE-2026-86239 liufee CVE debrief
CVE-2026-86239 is a medium-severity vulnerability in liufee FeehiCMS up to 2.1.1, specifically in the UeditorAction::init function of the UEditor Widget, allowing for unrestricted file upload. This vulnerability has a CVSS score of 5.5 and is considered medium severity. The exploit is publicly available, but there is no information on widespread exploitation. Defenders should verify the presence of this vulnerability, assess potential impact, and monitor for exploits. The project was informed of the problem early through an issue report but has not responded yet.
- Vendor
- liufee
- Product
- FeehiCMS
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
Defenders responsible for FeehiCMS installations, security teams assessing vulnerability impact, and administrators evaluating potential risks should be aware of this vulnerability.
Why it matters
CVE-2026-86239 is a medium-severity vulnerability in liufee FeehiCMS that allows for unrestricted file upload. Defenders should verify the presence of this vulnerability, assess potential impact, and monitor for exploits.
- Verify the presence of vulnerable FeehiCMS versions in your environment.
- Assess the potential impact of unrestricted file uploads on system security.
- Monitor for publicly available exploits and adjust defensive priorities.
- Evaluate the need for compensating controls to mitigate the vulnerability.
Technical summary
The vulnerability is located in the UeditorAction::init function of the UEditor Widget in liufee FeehiCMS up to 2.1.1. The manipulation leads to unrestricted upload, allowing remote exploitation. The exploit is publicly available. The CVE record and NVD entry provide information on the vulnerability, but there is limited information on affected versions, exploitation, or remediation. The vendor has not responded to the issue report. Defenders should prioritize verifying the presence of this vulnerability in their FeehiCMS installations and assessing the potential impact of unrestricted file uploads. The vulnerability allows for unrestricted file upload, which can lead to potential security risks if exploited. It is essential to verify the presence of vulnerable FeehiCMS versions in the environment and assess the potential impact of unrestricted file uploads on system security. Monitoring for publicly available exploits and adjusting defensive priorities is also crucial. Evaluating the need for compensating controls to mitigate the vulnerability is recommended. The vulnerability's impact can be significant if exploited, and defenders should take necessary precautions to prevent exploitation. The lack of response from the vendor adds to the urgency of addressing this vulnerability. Defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Planning vendor-supported updates or mitigations through normal change control where exposure is confirmed is essential. Reviewing compensating controls for exposed systems while remediation is scheduled and verified is also recommended. Checking relevant monitoring, detection, and logs for exposed assets that need extra review is crucial. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented is necessary. The vulnerability's details and potential impact should be carefully reviewed to ensure adequate protection. The exploit's availability and potential for remote exploitation make it essential to address this vulnerability promptly. The vulnerability's CVSS score of 5.5 indicates a medium severity level, but 5
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their FeehiCMS installations and assessing the potential impact of unrestricted file uploads.
Recommended defensive actions
- Verify the presence of FeehiCMS version 2.1.1 or earlier in your environment.
- Assess the potential impact of unrestricted file uploads on your system.
- Monitor for publicly available exploits and adjust defensive priorities accordingly.
- Consider implementing compensating controls to mitigate the vulnerability.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide information on the vulnerability, but there is limited information on affected versions, exploitation, or remediation. The vendor has not responded to the issue report.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86239 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86239
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86239 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86239
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/liufee/cms/issues/94
-
Source reference
Unverified legacy reference
URL: https://github.com/yang5ynag/cve/blob/main/FEHI-001-UEditor-Unauthorized-File-Upload.md
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-86239
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/901833
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/399396
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/399396/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.