Junglewise Threat Intelligence

CVE-2026-39393: ci4-cms-erp CI4MS authentication bypass in installation wizard

CVE-2026-39393 · Severity: high · CVSS 8.1 · Published 2026-04-08

Technologies: Ci4ms, ci4-cms-erp/ci4ms (Packagist). Vendors: Ci4ms, Packagist.

Executive brief

CI4MS is a content management system (CMS) used to build and manage websites. A security flaw allows unauthenticated attackers to hijack the entire application by tricking it into running the setup wizard again. If the website's database is temporarily unavailable, an attacker can overwrite the system's configuration file with their own settings, effectively redirecting all website data to a server they control and gaining full administrative access.

Technical details

The vulnerability exists in the `InstallFilter::before()` method, which relies on a volatile cache check (`cache('settings')`) and the existence of a `.env` file to block access to the installation wizard. During a cache miss (due to TTL expiry or admin-triggered clear) combined with a temporary database outage, the filter fails open because the application silently swallows database exceptions and leaves the cache empty. An unauthenticated attacker can then access the `/install` route, which is exempt from CSRF protection, and submit a POST request to overwrite the `.env` file with attacker-controlled database credentials. This results in a full application takeover, as the CMS will subsequently connect to the attacker's database for all operations. The issue is fixed in version 0.31.4.0 by implementing a persistent filesystem lock.

Affected products

  • ci4-cms-erp ci4ms < 0.31.4.0

Timeline

  • 2026-04-07: advisory: GitHub Security Advisory published
  • 2026-04-08: disclosed: CVE-2026-39393 published
  • 2026-04-08: patched: Vulnerability fixed in version 0.31.4.0

References

Related threats