PatchSiren cyber security CVE debrief
CVE-2026-9609 QianFox CVE debrief
A weak password recovery vulnerability exists in QianFox FoxCMS versions up to 1.2.6, specifically within the Edit function of the Admin.php file. The vulnerability allows remote attackers to manipulate password recovery mechanisms, potentially enabling unauthorized account access. The CVSS 4.0 score of 2.0 (LOW severity) reflects the requirement for high privileges (PR:H) to exploit this weakness. The vulnerability was reported to the project maintainers via GitHub issue prior to public disclosure, but no response has been received. Public exploit availability increases practical risk despite the low base score. Organizations using FoxCMS should monitor for vendor patches and consider implementing additional authentication controls.
- Vendor
- QianFox
- Product
- FoxCMS
- CVSS
- LOW 2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-07-23
Who should care
Organizations operating QianFox FoxCMS installations with administrative interfaces exposed to network access. Security teams responsible for content management system security and authentication controls. Developers maintaining FoxCMS forks or customizations. Incident response teams tracking publicly exploited authentication weaknesses.
Technical summary
The vulnerability resides in the Edit function of Admin.php within QianFox FoxCMS 1.2.6 and earlier. The implementation contains a weak password recovery mechanism (CWE-640) that can be manipulated remotely. Exploitation requires high privileges, limiting attack surface to authenticated administrative contexts. The CVSS 4.0 vector AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/E:P indicates network accessibility, low attack complexity, no user interaction, but high privilege requirements with low impact across confidentiality, integrity, and availability dimensions. Public exploit availability elevates practical concern for deployments with administrative access exposed or compromised.
Defensive priority
low
Recommended defensive actions
- Monitor QianFox FoxCMS GitHub repository for security patches addressing CVE-2026-9609
- Review and strengthen password recovery workflows in FoxCMS deployments
- Implement multi-factor authentication for administrative accounts to mitigate weak recovery risks
- Consider temporary access restrictions to Admin.php Edit functionality until patch available
- Document incident response procedures for potential account compromise via password recovery abuse
Evidence notes
Vulnerability identified in FoxCMS Admin.php Edit function. CWE-640 (Weak Password Recovery Mechanism for Forgotten Password) assigned. Exploit publicly available per Vuldb submission. Vendor notified via GitHub issue #3 without response. CVSS 4.0 vector confirms network attack vector with high privilege requirement.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-9609 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-9609
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-9609 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9609
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/QianFox/FoxCMS/
-
Source reference
Unverified legacy reference
URL: https://github.com/QianFox/FoxCMS/issues/3
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/818343
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/365682
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/365682/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.