CVE-2026-29014
MetInfo CMS Unauthenticated PHP Code Injection RCE
Description
MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.
In plain language
AI Act nowCVE-2026-29014 is a MetInfo CMS flaw that lets an attacker run PHP code on your server with no login; if you use MetInfo CMS versions 7.9–8.1, you should act quickly.
CVE-2026-29014 is an unauthenticated remote PHP code injection leading to remote code execution in MetInfo CMS (Metinfo/MetInfo CMS) via crafted requests, allowing arbitrary server-side code execution without authentication.
What to do now
- Check whether you are running MetInfo CMS (Metinfo/MetInfo CMS) version 7.9, 8.0, or 8.1.
- If you are on 7.9–8.1, follow the vendor’s remediation guidance immediately (see the MetInfo notice linked by CVE-2026-29014).
- Apply the vendor fix/upgrade path to a version MetInfo CMS releases as patched for this vulnerability.
- If patching is delayed, block direct internet access to the MetInfo CMS instance at the network level until you can remediate, and review logs for unusual requests targeting the CMS.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-29014 and every CVE in our database. Create a free account — no credit card required.
Create Free Account