PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-36239 PbootCMS CVE debrief

A code injection vulnerability has been identified in PbootCMS v.3.2.11 within its site configuration functionality. The vulnerability was published to the CVE Program on 26 May 2026. At this time, no CVSS score or severity rating has been assigned by NVD, and the vulnerability has not been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. The vendor attribution is currently marked as requiring review due to low confidence in the canonical source identification.

Vendor
PbootCMS
Product
PbootCMS 3.2.11
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-26
Original CVE updated
2026-07-23
Advisory published
2026-05-26
Advisory updated
2026-07-23

Who should care

Organizations operating PbootCMS v.3.2.11 instances, particularly those exposing administrative configuration interfaces to broader networks. Security teams responsible for content management system security and vulnerability management programs tracking emerging CVE disclosures.

Technical summary

CVE-2026-36239 describes a code injection vulnerability affecting PbootCMS version 3.2.11, specifically located in the site's configuration functionality. Code injection in configuration interfaces typically allows attackers with appropriate access to execute arbitrary code through manipulated configuration values, potentially leading to complete system compromise. The vulnerability was disclosed on 26 May 2026. No CVSS vector or CISA KEV listing is currently available. Organizations using PbootCMS should monitor for vendor security updates and apply defense-in-depth controls on administrative interfaces pending patch availability.

Defensive priority

medium

Recommended defensive actions

  • Review PbootCMS site configuration access controls and restrict administrative interfaces to trusted networks
  • Monitor for security advisories from the PbootCMS project regarding patched versions
  • Assess deployment of PbootCMS v.3.2.11 within your environment and consider upgrade paths pending vendor guidance
  • Implement input validation and output encoding for configuration parameters as defense-in-depth
  • Subscribe to NVD updates for this CVE to receive CVSS scoring and CPE assignments when available

Evidence notes

The CVE record indicates PbootCMS version 3.2.11 as the affected product. Source references include the PbootCMS project domain and a GitHub repository attributed to a researcher identifier. The vulnerability status in NVD is currently 'Received', indicating initial processing without completed analysis.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-36239 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-36239

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-36239 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-36239

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.