CVE-2026-21861Disclosure(basercms / basercms)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch basercms basercms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server due to improper handling of user-controlled input that is directly passed to exec() without sufficient validation or escaping. This issue has been patched in version 5.2.3.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • basercms

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 6 mentions (2026-03-31); latest day: 1
  • 7 total mentions across 2 days

Affected systems

Vendors
Products
basercms

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-03-31: 6Mentions · 2026-04-02: 1Patch / Workaround · 2026-03-31: 2Technical Details · 2026-03-31: 4Technical Details · 2026-04-02: 103-3104-02
Signal classification2 categories
Disclosure
571.4%
Patch
228.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-316
Disclosure4Patch2
2026-04-021
Disclosure1
Full discourse7 posts
  • kaminuma@kaminuma_dev
    Patch

    Two vulnerabilities I reported to baserCMS are now public: CVE-2026-21861 CVE-2026-30940 Thanks to the maintainers for the fix and disclosure. Advisory: https://basercms.net/security/JVN_20837860 #CVE #AppSec #Security

    Post summary

    The post announces that two baserCMS CVEs have been publicly disclosed and patched, with an advisory link provided. No PoC, exploit, or active exploitation information is mentioned.

    00030130
    137 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21861 baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An auth… https://www.cve.org/CVERecord?id=CVE-2026-21861

    Post summary

    The announcement reveals an OS command injection flaw in baserCMS versions before 5.2.3 that can be exploited via the core update feature.

    00010104
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-21861 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-21861 #CVE-2026-21861 #CVE #Critical #CyberSecurity #InfoSec https://t.co/4zQEsenI3r

    Post summary

    The tweet announces a new critical CVE with basic severity information but provides no technical, exploit, or mitigation details.

    0001027
    123 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-21861: CRITICAL] Critical OS command injection vulnerability patched in baserCMS version 5.2.3. Admins urged to update to secure against potential attacks exploiting improper user input handling.#cve,CVE-2026-21861,#cybersecurity https://cvefind.com/CVE-2026-21861

    Post summary

    A critical OS command injection vulnerability in baserCMS has been patched in version 5.2.3, and administrators are encouraged to update immediately.

    0001059
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-21861 - Critical baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrat... https://www.thehackerwire.com/vulnerability/CVE-2026-21861/ https://t.co/SHzyX1I8nW

    Post summary

    The post announces a critical OS command injection vulnerability (CVE-2026-21861) in baserCMS versions before 5.2.3, highlighting the affected core update functionality.

    0001054
    163 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    OS Command Injection RCE (CVE-2026-21861) identified in `baserCMS`. This allows arbitrary command execution. Review systems for exposure. #baserCMS #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-21861-basercms-rce

    Post summary

    The post announces the discovery of CVE‑2026‑21861 in baserCMS, a command‑injection RCE that permits arbitrary command execution.

    0000034
    6 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-21861: ba... Admin-to-root via exec() in baserCMS core updates - another CMS turning privileged users into system owners with zero effort required. #RCE #CMSFail. https://zerodaysignal.com/vulnerability/CVE-2026-21861 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑21861 as a privilege‑escalation RCE in baserCMS via exec(), without mentioning a PoC, exploit code, or patch, but does provide technical details about the vulnerability.

    0000051
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbasercmsbasercms---

Explore more