CVE-2026-32276Disclosure(opensource-workshop / connect-cms)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch opensource-workshop connect-cms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an authenticated user may be able to execute arbitrary code in the Code Study Plugin. Versions 1.41.1 and 2.41.1 contain a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connect-cms

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-23); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
connect-cms

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-23: 2Mentions · 2026-03-24: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 103-2303-24
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-232
Disclosure1Patch1
2026-03-241
General1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-32276 Authenticated Remote Code Execution in Connect-CMS Code Study Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32276

    Post summary

    A headline announces the discovery of an authenticated RCE vulnerability in Connect‑CMS Code Study Plugin, but provides no PoC, exploit, patch, or active exploitation details.

    0001054
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32276 - High Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an authenticated user may be ab... https://www.thehackerwire.com/vulnerability/CVE-2026-32276/ https://t.co/isZpKyz2A3

    Post summary

    A high‑severity CVE-2026-32276 has been disclosed for Connect‑CMS versions 1.x up to 1.41.0 and 2.x up to 2.41.0, but no further technical or mitigation details are provided.

    0000028
    145 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32276: HIGH] Cybersecurity alert: Connect-CMS versions 1.x up to 1.41.0 & versions 2.x up to 2.41.0 vulnerable to code execution in Code Study Plugin. Update to 1.41.1 or 2.41.1 to patch.#cve,CVE-2026-32276,#cybersecurity https://cvefind.com/CVE-2026-32276

    Post summary

    Connect‑CMS versions 1.x up to 1.41.0 and 2.x up to 2.41.0 are vulnerable to remote code execution in the Code Study Plugin; the issue is mitigated by updating to 1.41.1 or 2.41.1.

    0000032
    606 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensource-workshopconnect-cms---

Explore more