Beveiligingsadvies

CVE-2026-8739

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-17 07:45:12
Laatst bijgewerkt 2026-05-18 20:09:22
Toegewezen door VulDB
CVSS-score 6.9
Status PUBLISHED

Beschrijving

A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigComponent.java. The manipulation of the argument privatefile_key results in use of hard-coded cryptographic key . The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.