UNKNOWN NVD
CVE-2026-79362
Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged us
Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code.
References
- https://github.com/WoltLab/WCF/commit/c19789dbcc15663c648db1b196b6e6b05265b121
- https://www.woltlab.com/community/thread/319263-update-woltlab-suite-6-2-6-6-1-23/
- https://www.woltlab.com/community/thread/319264-aktualisierung-woltlab-suite-6-2-6-6-1-23/
This unknown severity vulnerability was published on 2026-09-11 via NVD.
vulnfeed aggregates 12842 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.