
🚀 CVE‑2026‑30993 – Slah CMS pre‑auth RCE (Critical): In Slah CMS v1.5.0 and below, an input handling bug in the session() function of config.php allows remote unauthenticated attackers to execute arbitrary PHP code via crafted parameters to the login/session logic, leading to full CMS takeover. CVSS 9.8 (v3.0), published 2026‑04‑16; patch by upgrading to a fixed Slah CMS release or applying the vendor’s config.php hotfix. https://www.tenable.com/cve/CVE-2026-30993 #CVE202630993 #SlahCMS #RCE #WebAppSec #ThreatIntel
Post summary
The text announces CVE‑2026‑30993, details a remote unauthenticated RCE vulnerability with a high CVSS score and provides clear patch guidance by upgrading or applying a hotfix.


