CVE-2026-30993Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploitable via a crafted input.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-16); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-16: 2Mentions · 2026-04-17: 1Patch / Workaround · 2026-04-16: 2Technical Details · 2026-04-16: 2Technical Details · 2026-04-17: 104-1604-17
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-162
Disclosure1Patch1
2026-04-171
Disclosure1
Full discourse3 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🚀 CVE‑2026‑30993 – Slah CMS pre‑auth RCE (Critical): In Slah CMS v1.5.0 and below, an input handling bug in the session() function of config.php allows remote unauthenticated attackers to execute arbitrary PHP code via crafted parameters to the login/session logic, leading to full CMS takeover. CVSS 9.8 (v3.0), published 2026‑04‑16; patch by upgrading to a fixed Slah CMS release or applying the vendor’s config.php hotfix. https://www.tenable.com/cve/CVE-2026-30993 #CVE202630993 #SlahCMS #RCE #WebAppSec #ThreatIntel

    Post summary

    The text announces CVE‑2026‑30993, details a remote unauthenticated RCE vulnerability with a high CVSS score and provides clear patch guidance by upgrading or applying a hotfix.

    1002042
    855 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🚀 CVE‑2026‑30993 – Slah CMS pre‑auth RCE (Critical): In Slah CMS v1.5.0 and below, an input handling bug in the session() function of config.php allows remote unauthenticated attackers to execute arbitrary PHP code via crafted parameters to the login/session logic, leading to full CMS takeover. CVSS 9.8 (v3.0), published 2026‑04‑16; patch by upgrading to a fixed Slah CMS release or applying the vendor’s config.php hotfix. https://www.tenable.com/cve/CVE-2026-30993 #CVE202630993 #SlahCMS #RCE #WebAppSec #ThreatIntel

    Post summary

    CVE‑2026‑30993 is a critical pre‑authentication remote code execution bug in Slah CMS, with a high CVSS score and an available patch that requires upgrading or applying a config.php hotfix.

    1002031
    1.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30993 Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploit… https://www.cve.org/CVERecord?id=CVE-2026-30993

    Post summary

    CVE-2026-30993 is a remote code execution vulnerability affecting Slah CMS v1.5.0 and below, targeting the session() function in config.php; no PoC, exploit code, or mitigation is provided in the text.

    0000088
    57.2K followersView on X

Explore more