PatchSiren cyber security CVE debrief
CVE-2026-36239 PbootCMS CVE debrief
A code injection vulnerability has been identified in PbootCMS v.3.2.11 within its site configuration functionality. The vulnerability was published to the CVE Program on 26 May 2026. At this time, no CVSS score or severity rating has been assigned by NVD, and the vulnerability has not been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. The vendor attribution is currently marked as requiring review due to low confidence in the canonical source identification.
- Vendor
- PbootCMS
- Product
- PbootCMS 3.2.11
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-07-23
Who should care
Organizations operating PbootCMS v.3.2.11 instances, particularly those exposing administrative configuration interfaces to broader networks. Security teams responsible for content management system security and vulnerability management programs tracking emerging CVE disclosures.
Technical summary
CVE-2026-36239 describes a code injection vulnerability affecting PbootCMS version 3.2.11, specifically located in the site's configuration functionality. Code injection in configuration interfaces typically allows attackers with appropriate access to execute arbitrary code through manipulated configuration values, potentially leading to complete system compromise. The vulnerability was disclosed on 26 May 2026. No CVSS vector or CISA KEV listing is currently available. Organizations using PbootCMS should monitor for vendor security updates and apply defense-in-depth controls on administrative interfaces pending patch availability.
Defensive priority
medium
Recommended defensive actions
- Review PbootCMS site configuration access controls and restrict administrative interfaces to trusted networks
- Monitor for security advisories from the PbootCMS project regarding patched versions
- Assess deployment of PbootCMS v.3.2.11 within your environment and consider upgrade paths pending vendor guidance
- Implement input validation and output encoding for configuration parameters as defense-in-depth
- Subscribe to NVD updates for this CVE to receive CVSS scoring and CPE assignments when available
Evidence notes
The CVE record indicates PbootCMS version 3.2.11 as the affected product. Source references include the PbootCMS project domain and a GitHub repository attributed to a researcher identifier. The vulnerability status in NVD is currently 'Received', indicating initial processing without completed analysis.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-36239 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-36239
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-36239 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-36239
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/TazmiDev/CVE-2026-36239
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.