CVE-2026-41202Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.5.0, ci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. This issue has been patched in version 0.31.5.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-05-07)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-23: 1Mentions · 2026-05-07: 3Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-23: 1Technical Details · 2026-05-07: 104-2305-07
Signal classification1 categories
Disclosure
4100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-231
Disclosure1
2026-05-073
Disclosure3
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-41202 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.5.… https://www.cve.org/CVERecord?id=CVE-2026-41202

    Post summary

    The statement gives a brief disclosure of CVE-2026-41202 affecting CI4MS, noting earlier versions are vulnerable, but lacks any PoC, exploit details, active exploitation reports, patch information, or technical specifics.

    00000103
    57.4K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-41202 📊 Severity: 9.4 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41202 #CVE-2026-41202 #CVE #Critical #CyberSecurity #InfoSec https://t.co/QReooJLHsJ

    Post summary

    The post announces a newly identified CVE‑2026‑41202 with a 9.4 severity score affecting multiple unspecified products, but offers no further technical or mitigation details.

    0000052
    152 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41202 Arbitrary File Write and Remote Code Execution in CI4MS Before 0.31.5.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41202 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The text announces the disclosure of CVE-2026-41202, describing an arbitrary file write and RCE flaw in CI4MS versions before 0.31.5.0, and provides links to detailed vulnerability information and alerts.

    0000040
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `CI4MS Backup::restore` is vulnerable to a Zip Slip flaw (CVE-2026-41202) leading to RCE. Validate archive inputs and run restore processes with least privilege. #infosec #RCE #Vulnerability https://www.pulsepatch.io/posts/cve-2026-41202-ci4ms-backup-zip-slip-rce

    Post summary

    The post discloses that CI4MS Backup::restore contains a Zip Slip vulnerability (CVE-2026-41202) capable of RCE and advises mitigating by validating inputs and running restores with least privilege.

    0000057
    12 followersView on X

Explore more