CVE-2026-29909 is an unauthenticated directory enumeration vulnerability affecting MRCMS V3.1.2. The flaw resides in the file management module's /admin/file/list.do endpoint, which lacks authentication and input validation, allowing remote attackers to list server directory contents without credentials. Rated as CVSS 5.3 MEDIUM, this vulnerability has a network attack vector with low complexity, potentially impacting confidentiality. There is currently no evidence of active exploitation, no public exploit code, and minimal community or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.2CPE matchmatch criteria | cpe:2.3:a:mrcms:mrcms:3.1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.