What is CVE-2026-55578?
CVE-2026-55578 is a vulnerability in Pheditor, a PHP single-file editor, where the terminal feature uses an incomplete character blocklist to sanitize commands, leading to potential remote code execution (RCE). It affects versions from 2.0.1 to before 2.0.6. Users must upgrade to version 2.0.6 or newer immediately.
Azərbaycanca: CVE-2026-55578 Pheditor adlı PHP əsaslı fayl redaktorunda terminal əməliyyatlarını məhdudlaşdıran natamam simvol qara siyahısı zəifliyidir. Bu, versiya 2.0.1-dən 2.0.6-dək təsir edir və uzaqdan kod icrasına (RCE) səbəb ola bilər. İstifadəçilər dərhal 2.0.6 versiyasına və ya daha yenisinə yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which versions of Pheditor are affected by CVE-2026-55578?
The vulnerability affects Pheditor versions from 2.0.1 to before 2.0.6. Users must upgrade to version 2.0.6 or newer immediately.
What is the main risk of CVE-2026-55578?
Due to an incomplete character blocklist sanitizing terminal commands, the vulnerability can lead to remote code execution (RCE).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.