CVE-2026-8500Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-13); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 105-1305-1405-15
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-8500 Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The us… https://www.cve.org/CVERecord?id=CVE-2026-8500

    Post summary

    A brief announcement that Web::Passwd versions through 0.03 for Perl are vulnerable to remote code execution, with no further exploit or mitigation information provided.

    0001081
    57.5K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-8500: Web::Passwd through 0.03 vulnerable to RCE https://www.openwall.com/lists/oss-security/2026/05/13/8 CVE-2026-8612: WWW::Mechanize::Cached before 2.00 deserialize HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution https://www.openwall.com/lists/oss-security/2026/05/15/1

    Post summary

    The text discloses two new Perl CPAN module vulnerabilities—CVE‑2026‑8500 (RCE) and CVE‑2026‑8612 (local response forgery leading to code execution)—but does not provide exploits or PoC evidence.

    00000180
    4.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8500 Remote Code Execution in Web::Passwd Perl Module Through 0.03 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8500

    Post summary

    The post announces a newly disclosed vulnerability (Remote Code Execution in the Web::Passwd Perl module) with basic technical details, but provides no PoC, exploit code, patch information, or evidence of active exploitation.

    0000063
    4.0K followersView on X

Explore more