PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105123 vincent-peugnet CVE debrief

CVE-2026-105123 is a remote code execution vulnerability in the vincent-peugnet/wcms product. Authenticated editors can write arbitrary files by abusing the unvalidated path in the media upload API, allowing for arbitrary file writes and potential code execution. The vulnerability can be exploited using encoded ../ sequences to write outside the media directory, and arbitrary files can be deleted via the DELETE /api/v0/media/[*:path] endpoint. Defenders should prioritize verifying exposure and assessing potential impact, as the vulnerability allows for arbitrary file writes and potential code execution.

Vendor
vincent-peugnet
Product
wcms
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-04
Original CVE updated
2026-10-04
Advisory published
2026-10-04
Advisory updated
2026-10-04

Who should care

Defenders responsible for the vincent-peugnet/wcms product, particularly those who manage web applications and APIs, should assess exposure and potential impact. Additionally, security teams and administrators who oversee the deployment and maintenance of this product should prioritize verifying exposure and implementing compensating controls.

Why it matters

CVE-2026-105123 is a remote code execution vulnerability in the vincent-peugnet/wcms product that allows authenticated editors to write arbitrary files via the media upload API. Defenders should prioritize verifying exposure and assessing potential impact, as the vulnerability can lead to code execution, data breaches, or system compromise. The vulnerability requires verification from official sources, and patches or updates should be applied if available.

  • Potential code execution via arbitrary file writes
  • Arbitrary file deletion via the DELETE /api/v0/media/[*:path] endpoint
  • Elevation of privileges for authenticated editors
  • Potential data breaches or system compromise

Technical summary

The vulnerability is caused by an unvalidated path in the media upload API, allowing authenticated editors to write arbitrary files, including PHP files that can be executed by the web server. The vulnerability can be exploited using encoded ../ sequences to write outside the media directory, and arbitrary files can be deleted via the DELETE /api/v0/media/[*:path] endpoint. The vulnerability requires verification from official sources, and patches or updates should be applied if available. Defenders should prioritize verifying exposure and assessing potential impact, as the vulnerability allows for arbitrary file writes and potential code execution.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact, as the vulnerability allows for arbitrary file writes and potential code execution.

Recommended defensive actions

  • Verify exposure by checking if the vincent-peugnet/wcms product is in use and if the media upload API is accessible to authenticated editors.
  • Assess potential impact by evaluating the sensitivity of data stored on the system and the potential consequences of arbitrary file writes and code execution.
  • Implement compensating controls, such as restricting access to the media upload API or monitoring for suspicious activity.
  • Apply patches or updates provided by the vendor, if available.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability is described in the CVE record and NVD entry, with additional details provided by source references, including GitHub repositories and a VulnCheck advisory. The CVE record was published on 2026-10-04T00:16:35.703Z and has not been modified since then. The vulnerability requires verification from official sources, and patches or updates should be applied if available. The media upload API is accessible to authenticated editors, and defenders should verify exposure and assess potential impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105123 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105123

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105123 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105123

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.