MetInfo CMS Vulnerability CVE-2026-29014 Allows Arbitrary Code Execution
Patch MetInfo to the latest release (8.2+) immediately.
Patch MetInfo to the latest release (8.2+) immediately.
Summary
MetInfo, an open‑source CMS, has a critical vulnerability (CVE‑2026‑29014) that allows unauthenticated PHP code injection, leading to arbitrary code execution.
The flaw, with a CVSS score of 9.8, affects versions 7.9, 8.0, and 8.1. Threat actors are actively exploiting the issue, meaning that any site running the vulnerable releases is at immediate risk. The injection point is not protected by authentication, so an attacker can submit malicious payloads via the public interface.
No patch has been released yet, but the vendor has announced a fix in the upcoming 8.2 update. Site owners should update immediately to avoid compromise. Monitoring for unusual PHP execution patterns is also recommended until the patch is applied.
Key changes
- CVE‑2026‑29014 is a PHP code injection flaw
- CVSS score 9.8 indicates critical severity
- Unauthenticated access allows arbitrary code execution
- Affects MetInfo CMS 7.9, 8.0, and 8.1
- Threat actors are actively exploiting the vulnerability
- Vendor plans a fix in the upcoming 8.2 release