CVE-2026-21861 is an OS command injection vulnerability affecting baserCMS versions prior to 5.2.3, where an authenticated administrator can execute arbitrary operating system commands on the server. This critical flaw, rated 7.2 HIGH, arises from improper handling of user-controlled input within the core update functionality, leading to potential full system compromise. Although there is no evidence of active exploitation or public exploit code, the vulnerability has received community attention, with discussions emphasizing its critical impact and the urgent need for patching to version 5.2.3 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.3CPE matchmatch criteria | cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.