Skip to content
Threat Feed
high advisory

Remote Code Execution in W CMS via Path Traversal

W CMS versions 3.18.0 and earlier are vulnerable to remote code execution and arbitrary file deletion due to insufficient path validation in the media management API.

CVE search metadata

CVE search record: CVE-2026-105123. Severity: high. CVSS: 8.8. KEV: no. Product: W (<= 3.18.0). Brief: Remote Code Execution in W CMS via Path Traversal. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wcms-rce/

W CMS (vincent-peugnet/wcms) through version 3.18.0 contains a critical remote code execution vulnerability originating from improper input validation within the API endpoints responsible for media management. Authenticated editors can exploit the path handling logic in the /api/v0/media/upload/[:path] endpoint to perform path traversal. By utilizing encoded dot-dot-slash (../) sequences, an attacker can bypass directory restrictions to write files, including malicious .php scripts, outside the intended media storage directory. Once placed, these scripts can be executed by the web server. Additionally, the /api/v0/media/[:path] endpoint is vulnerable to arbitrary file deletion, allowing authenticated users to disrupt the application or remove security configuration files. This vulnerability represents a significant risk to the integrity and availability of the host server environment.

Attack Chain

  1. Attacker authenticates as an editor user within the target W CMS instance.
  2. Attacker crafts a malicious HTTP POST request to /api/v0/media/upload/[*:path].
  3. The request includes an encoded directory traversal sequence (e.g., %2e%2e%2f) within the path parameter.
  4. The application fails to sanitize the path, allowing the attacker to target sensitive web-accessible directories.
  5. The attacker uploads a web shell disguised as a .php file to an executable location.
  6. The attacker navigates to the location of the uploaded file via the browser to trigger code execution.
  7. Optional: The attacker uses the DELETE method on /api/v0/media/[*:path] to remove application logs or critical files for post-exploitation cleanup.

Impact

Successful exploitation grants an authenticated editor full remote code execution capabilities on the underlying host server. This allows for total system compromise, including the ability to exfiltrate data, modify web content, or pivot into the internal network. Attackers may also cause denial-of-service conditions by deleting arbitrary application files necessary for CMS functionality.

Recommendation

Prioritized, concrete actions for detection engineering teams:

  • Upgrade W CMS to a version beyond 3.18.0 immediately to remediate CVE-2026-105123.
  • Deploy the Sigma rules provided in this brief to detect anomalous API requests targeting the media management endpoints.
  • Implement access control reviews for accounts with "editor" permissions, as these are the primary vector for this vulnerability.
  • Monitor web server access logs for anomalous POST and DELETE requests to /api/v0/media/ paths containing path traversal characters like "../" or URL-encoded equivalents.

Immediate actions

Upgrade W CMS to latest version beyond 3.18.0

IT Operations 48h

Mitigations

Upgrade to latest version

immediate IT Operations

CVE-2026-105123

Detection coverage 1

Detect CVE-2026-105123 Exploitation - Path Traversal in Media API

high

Detects exploitation attempts against CVE-2026-105123 where an attacker uses path traversal sequences to reach outside the media directory

sigma tactics: initial_access techniques: T1190, T1203 sources: webserver

Detection queries are available on the platform. Get full rules →