OVERVIEW CVE-2026-6257 is a remote code execution vulnerability affecting Vvveb CMS v1.0.8, located in the media management functionality. A missing return statement in the file rename handler permits authenticated attackers to rename files to dangerous extensions including .php and .htaccess, bypassing extension-based access controls. SEVERITY This vulnerability carries a CVSS v3.1 score of 9.1 (CRITICAL) with a network-based attack vector requiring high-level privileges but no user interaction. The attack has significant scope and impact, enabling compromise of confidentiality, integrity, and availability. Exploitation involves a two-stage attack where an attacker first renames an uploaded text file to .htaccess to inject Apache directives that register PHP as an executable MIME type, then uploads and renames a second file to .php to execute arbitrary operating system commands with www-data user privileges. EXPLOITATION STATUS Active exploitation of this vulnerability appears limited. It is not currently tracked on the CISA Known Exploited Vulnerabilities catalog and has no public exploit code listed on exploit databases. The EPSS score of 0.0024 indicates this vulnerability ranks lower than approximately 99.5 percent of all CVEs in terms of probability of exploitation, suggesting minimal community or threat actor attention at present.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Vvveb | Vvveb CMS | 1.0.8.2CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.