Vendor
Pheditor Authentication Bypass via Unverified Current Password in Forced Password Change
3 TTPsA critical authentication bypass vulnerability in Pheditor versions prior to 2.0.8 allows an unauthenticated attacker to gain full administrative access by exploiting a flaw in the forced password-change flow, enabling them to set an arbitrary new admin password and obtain an authenticated session without knowing the current one.
Pheditor Terminal Argument Injection Leads to Remote Code Execution
4 rules 2 TTPsA vulnerability in Pheditor's terminal feature (versions <= 2.0.6) allows authenticated attackers to achieve arbitrary command execution via argument injection into allowlisted binaries, which can be chained with default credentials for effective unauthenticated remote code execution on the underlying host.
Pheditor Hardcoded Admin Password Leads to Remote Code Execution (CVE-2026-55579)
1 rule 5 TTPsPheditor contains a critical vulnerability (CVE-2026-55579) where a hardcoded default password 'admin' with no forced change mechanism upon first login allows an unauthenticated attacker to gain full administrative access, enabling arbitrary file read/write and remote code execution through the application's terminal feature, leading to complete server compromise.
Pheditor Authenticated Command Whitelist Bypass via Shell Command Substitution
1 rule 1 TTPPheditor 2.0.4 contains an authenticated command injection vulnerability, CVE-2026-54540, allowing a user with `terminal` permissions to bypass the `TERMINAL_COMMANDS` whitelist by leveraging shell command substitution to execute arbitrary shell commands as the web server user.