CVE-2026-8500 Details
Description
Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection.
A remote code execution vulnerability exists in Web::Passwd versions through 0.03 for Perl. This small CGI application manages htpasswd files using the htpasswd command. The vulnerability arises because the user parameter is not properly validated or escaped, allowing for command injection by injecting malicious commands that are executed on the server.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 13, 2026CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://httpd.apache.org/docs/current/programs/htpasswd.html | CPANSec | |
| https://metacpan.org/release/EVANK/Web-Passwd-0.03 | CPANSec | ProductVendor |
| http://www.openwall.com/lists/oss-security/2026/05/13/8 | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CPANSec |
Affected Products
| Product | Versions |
|---|---|
| EVANK Web::Passwd | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CPANSec |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | CVE Modified | CVE |
| May 13, 2026 | New CVE Received | CPANSec |
Volerion