Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6257

31
FAUCET Score

OVERVIEW CVE-2026-6257 is a remote code execution vulnerability affecting Vvveb CMS v1.0.8, located in the media management functionality. A missing return statement in the file rename handler permits authenticated attackers to rename files to dangerous extensions including .php and .htaccess, bypassing extension-based access controls. SEVERITY This vulnerability carries a CVSS v3.1 score of 9.1 (CRITICAL) with a network-based attack vector requiring high-level privileges but no user interaction. The attack has significant scope and impact, enabling compromise of confidentiality, integrity, and availability. Exploitation involves a two-stage attack where an attacker first renames an uploaded text file to .htaccess to inject Apache directives that register PHP as an executable MIME type, then uploads and renames a second file to .php to execute arbitrary operating system commands with www-data user privileges. EXPLOITATION STATUS Active exploitation of this vulnerability appears limited. It is not currently tracked on the CISA Known Exploited Vulnerabilities catalog and has no public exploit code listed on exploit databases. The EPSS score of 0.0024 indicates this vulnerability ranks lower than approximately 99.5 percent of all CVEs in terms of probability of exploitation, suggesting minimal community or threat actor attention at present.

Impacted Technologies

VendorProductVersion(s)CPE
VvvebVvveb CMS
1.0.8.2CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

9.2CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
HIGH
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.63%
Probability of exploitation in next 30 days
EPSS Percentile
46.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0063 is in the 38th percentile among its peer group of 464 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / givanz/Vvveb/commit/6fb8eaa998265e33e8802cbc220d8859dbc144f2
vulncheck.com / advisories/vvveb-cms-remote-code-execution-via-media-management