Briefing

MetInfo CMS Vulnerability CVE-2026-29014 Allows Arbitrary Code Execution

security
by [email protected] (The Hacker News) · CVE-2026-29014

Patch MetInfo to the latest release (8.2+) immediately.

What to do now

Patch MetInfo to the latest release (8.2+) immediately.

Summary

MetInfo, an open‑source CMS, has a critical vulnerability (CVE‑2026‑29014) that allows unauthenticated PHP code injection, leading to arbitrary code execution.

The flaw, with a CVSS score of 9.8, affects versions 7.9, 8.0, and 8.1. Threat actors are actively exploiting the issue, meaning that any site running the vulnerable releases is at immediate risk. The injection point is not protected by authentication, so an attacker can submit malicious payloads via the public interface.

No patch has been released yet, but the vendor has announced a fix in the upcoming 8.2 update. Site owners should update immediately to avoid compromise. Monitoring for unusual PHP execution patterns is also recommended until the patch is applied.

Key changes

  • CVE‑2026‑29014 is a PHP code injection flaw
  • CVSS score 9.8 indicates critical severity
  • Unauthenticated access allows arbitrary code execution
  • Affects MetInfo CMS 7.9, 8.0, and 8.1
  • Threat actors are actively exploiting the vulnerability
  • Vendor plans a fix in the upcoming 8.2 release

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting