{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/w--3.18.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vincent-peugnet:w:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-105123"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["W (\u003c= 3.18.0)"],"_cs_severities":["high"],"_cs_tags":["web-application","rce","vulnerability","path-traversal"],"_cs_type":"advisory","_cs_vendors":["Vincent Peugnet"],"content_html":"\u003cp\u003eW CMS (vincent-peugnet/wcms) through version 3.18.0 contains a critical remote code execution vulnerability originating from improper input validation within the API endpoints responsible for media management. Authenticated editors can exploit the path handling logic in the /api/v0/media/upload/[\u003cem\u003e:path] endpoint to perform path traversal. By utilizing encoded dot-dot-slash (../) sequences, an attacker can bypass directory restrictions to write files, including malicious .php scripts, outside the intended media storage directory. Once placed, these scripts can be executed by the web server. Additionally, the /api/v0/media/[\u003c/em\u003e:path] endpoint is vulnerable to arbitrary file deletion, allowing authenticated users to disrupt the application or remove security configuration files. This vulnerability represents a significant risk to the integrity and availability of the host server environment.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates as an editor user within the target W CMS instance.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request to /api/v0/media/upload/[*:path].\u003c/li\u003e\n\u003cli\u003eThe request includes an encoded directory traversal sequence (e.g., %2e%2e%2f) within the path parameter.\u003c/li\u003e\n\u003cli\u003eThe application fails to sanitize the path, allowing the attacker to target sensitive web-accessible directories.\u003c/li\u003e\n\u003cli\u003eThe attacker uploads a web shell disguised as a .php file to an executable location.\u003c/li\u003e\n\u003cli\u003eThe attacker navigates to the location of the uploaded file via the browser to trigger code execution.\u003c/li\u003e\n\u003cli\u003eOptional: The attacker uses the DELETE method on /api/v0/media/[*:path] to remove application logs or critical files for post-exploitation cleanup.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an authenticated editor full remote code execution capabilities on the underlying host server. This allows for total system compromise, including the ability to exfiltrate data, modify web content, or pivot into the internal network. Attackers may also cause denial-of-service conditions by deleting arbitrary application files necessary for CMS functionality.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade W CMS to a version beyond 3.18.0 immediately to remediate CVE-2026-105123.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules provided in this brief to detect anomalous API requests targeting the media management endpoints.\u003c/li\u003e\n\u003cli\u003eImplement access control reviews for accounts with \u0026quot;editor\u0026quot; permissions, as these are the primary vector for this vulnerability.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST and DELETE requests to /api/v0/media/ paths containing path traversal characters like \u0026quot;../\u0026quot; or URL-encoded equivalents.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-04T05:00:08Z","date_published":"2026-10-04T05:00:08Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wcms-rce/","summary":"W CMS versions 3.18.0 and earlier are vulnerable to remote code execution and arbitrary file deletion due to insufficient path validation in the media management API.","title":"Remote Code Execution in W CMS via Path Traversal","url":"https://feed.craftedsignal.io/briefs/2026-10-wcms-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - W (\u003c= 3.18.0)","version":"https://jsonfeed.org/version/1.1"}