Junglewise Threat Intelligence

CVE-2026-38615: DedeCMS command execution in file_manage_control.php

CVE-2026-38615 · Severity: info · CVSS 9.8 · Published 2026-06-09

Technologies: DedeCMS. Vendors: DedeCMS.

Executive brief

DedeCMS, a popular content management system, contains a critical security flaw in its file management component. An attacker can exploit this to run unauthorized commands on the underlying web server. This could lead to a total takeover of the website, theft of sensitive customer data, or the installation of malware.

Technical details

A command execution vulnerability exists in DedeCMS V5.7.118 within the file_manage_control.php script. The flaw likely stems from insufficient sanitization of user-supplied input passed to system-level functions or through insecure file handling logic. A remote attacker can exploit this vulnerability by sending a specially crafted request to the affected script, allowing for the execution of arbitrary OS commands. This typically results in full system compromise under the privileges of the web server user. While the advisory does not explicitly state authentication requirements, command execution in file management modules often bypasses or exploits administrative interfaces.

Affected products

  • DedeCMS DedeCMS V5.7.118

Timeline

  • 2026-06-09: disclosed: Initial disclosure and NVD publication

References

Related threats