What is CVE-2026-73679?
An authenticated remote code execution vulnerability has been identified in ImpressCMS within the custom tag module. Authenticated administrators can execute arbitrary PHP code by storing a malicious payload in a custom tag with PHP type enabled, exploiting HTML decoding via the undoHtmlSpec function. Affected systems should be patched immediately.
Azərbaycanca: ImpressCMS platformasında autentifikasiya olunmuş administratorlar üçün uzaqdan kod icrası (RCE) zəifliyi aşkar edilib. Təcavüzkar, PHP tipli xüsusi teqdə (custom tag) undoHtmlSpec funksiyası vasitəsilə HTML-dekodlanmış zərərli yük yerləşdirərək ixtiyari PHP kodu icra edə bilər. Bu problem autentifikasiya olunmuş inzibatçılara təsir edir, dərhal proqram təminatını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Who can exploit the ImpressCMS CVE-2026-73679 vulnerability?
Only authenticated administrators can exploit this vulnerability.
How is arbitrary PHP code executed in CVE-2026-73679?
Arbitrary PHP code is executed by placing an HTML-decoded malicious payload in a custom tag with PHP type enabled, exploiting the undoHtmlSpec function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.