CVE-2026-39918Disclosure

LOWCVSS 9.2 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized into the env.php configuration file without escaping or validation. Attackers can inject arbitrary PHP code by breaking out of the string context in the define statement to achieve unauthenticated remote code execution as the web server user.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-20); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-04-20: 3Mentions · 2026-04-21: 2PoC Mentioned / Linked · 2026-04-20: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-20: 2Technical Details · 2026-04-21: 204-2004-21
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-203
Disclosure2Patch1
2026-04-212
Disclosure1Patch1
Full discourse5 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-39918 — CVSS 9.8/10 ██████████ Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/dddGxjsVk1

    Post summary

    A critical code injection vulnerability (CVE‑2026‑39918) with CVSS 9.8/10 is disclosed, and a patch is now available.

    1000047
    28 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39918 Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized into the env.php co… https://www.cve.org/CVERecord?id=CVE-2026-39918

    Post summary

    The text announces a code injection vulnerability in Vvveb versions prior to 1.0.8.1, arising from unsanitized handling of the subdir POST parameter in the installation endpoint.

    0000095
    57.2K followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Cloud-native deployments (CVSS 9.8-9.9) Affected: Spinnaker; Doorman; Vvveb; SGLang Internet-facing risks dominate, led by cloud-native deployments and identity/access flaws; fixes and mitigations below. • CVE-2026-32604 (CVSS 9.9) Spinnaker allows remote command execution on clouddriver pods via unauthenticated access; affected versions prior to 2026.1.0, 2026.0.1, 2025.4.2, 2025.3.2. • CVE-2026-32613 (CVSS 9.9) Spinnaker SPeL context allowed full JVM access enabling arbitrary Java class usage to invoke commands and access files; affected versions prior to 2026.1.0, 2026.0.1, 2025.4.2, 2025.3.2. • CVE-2026-30269 (CVSS 9.9) Doorman improper access control allows authenticated users to escalate their own role to non-admin via /platform/user/{username}; affected versions v0.1.0 and v1.0.2. • CVE-2026-39918 (CVSS 9.8) Vvveb installation endpoint vulnerability: the subdir POST parameter is written unsanitized into env.php, enabling unauthenticated remote code execution as the web server user; affected versions prior to 1.0.8.1. • CVE-2026-5760 (CVSS 9.8) SGLang reranking endpoint /v1/rerank enables remote code execution when a model file contains a malicious http://tokenizer.chat_template; affects SGLang prior to 0.5.9. 🛠️ Action - Patch/upgrade to fixed versions called out (Spinnaker 2026.1.0+; Doorman latest; Vvveb 1.0.8.1+; SGLang 0.5.9+). - Prioritize internet-facing instances and edge appliances first. - If mitigation is needed, apply available mitigations and reduce exposure where fixes are not yet deployed. - Add detections for exploitation patterns (unauthenticated RCE attempts, suspicious file-write paths, unexpected process spawns). - Hunt for indicators around affected services during disclosure-to-now window (logs, EDR, WAF). - Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post details critical CVEs across several cloud-native products, provides explicit technical descriptions of the vulnerabilities, and delivers actionable patch and mitigation guidance.

    0000095
    99 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39918 Code Injection in Vvveb Prior to 1.0.8.1 Installation Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39918

    Post summary

    The text simply identifies CVE‑2026‑39918 and links to a vulnerability detail page, with no additional technical, exploit, or mitigation information.

    0000036
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-39918: Vv... String breakout in installation endpoint writes unsanitized PHP directly to env.php - classic define() injection for instant RCE #RCE #CodeInjection. https://zerodaysignal.com/vulnerability/CVE-2026-39918 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-39918, detailing how a string breakout in the installation endpoint allows attackers to write unsanitized PHP to env.php, resulting in remote code execution, with no mention of active exploitation or available patches.

    0000072
    218 followersView on X

Explore more