Junglewise Threat Intelligence

CVE-2026-39389: ci4-cms-erp CI4MS authorization bypass in Fileeditor

CVE-2026-39389 · Severity: medium · CVSS 6.7 · Published 2026-04-08

Technologies: ci4-cms-erp/ci4ms (Packagist), Ci4-Cms-Erp Ci4ms. Vendors: Packagist.

Executive brief

CI4MS, a content management system based on CodeIgniter 4, contains a security flaw in its file management component. An authorized backend user can bypass intended restrictions to read sensitive configuration files (like database passwords and encryption keys) or modify critical system files. This could lead to the theft of administrative credentials, a complete takeover of the web server, or a disruption of service.

Technical details

An improper authorization vulnerability exists in the Fileeditor controller of CI4MS. While the application defines a 'hiddenItems' array to protect sensitive files like .env and composer.json, this check was only implemented in the directory listing method (listFiles). Other API endpoints—including readFile, saveFile, deleteFileOrFolder, renameFile, and createFile—lacked these checks. A network-based attacker with backend 'fileeditor.read' privileges can exfiltrate secrets from the .env file, while those with 'fileeditor.update' privileges can overwrite composer.json to achieve remote code execution (RCE) via composer scripts. Additionally, CSRF protection was explicitly disabled for these routes, increasing the risk of exploitation. The issue is fixed in version 0.31.4.0.

Affected products

  • ci4-cms-erp CI4MS < 0.31.4.0

Timeline

  • 2026-04-07: advisory: GitHub Security Advisory published
  • 2026-04-08: disclosed: CVE-2026-39389 published to NVD
  • 2026-04-08: patched: Vulnerability fixed in version 0.31.4.0

References

Related threats