CVE-2026-54611 Details
Description
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix.
A remote code execution vulnerability has been identified in InstantCMS versions prior to 2.18.2. This issue allows remote authenticated attackers to execute PHP code through the component installer. The vulnerability arises from the ability to upload a malicious component to the server. While the uploaded component is not installed, the files can be executed. Typically, PHP files in the upload directory are not executed; however, by uploading a custom .htaccess file, this restriction can be bypassed. Version 2.18.2 addresses this vulnerability.
Users can update to InstantCMS version 2.18.2 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/instantsoft/icms2/security/advisories/GHSA-vvgv-h28h-p2m5 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/instantsoft/icms2/commit/44f3a9d04a3207c82cdc756599cbdf084a02858f | [email protected] | Source CodeVendor |
| https://github.com/instantsoft/icms2/security/advisories/GHSA-vvgv-h28h-p2m5 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| InstantCMS | <= 2.17.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion