Junglewise Threat Intelligence

CVE-2026-67960: PbootCMS remote code execution in controller files

CVE-2026-67960 · Severity: critical · CVSS 9.8 · Published 2026-08-17

Executive brief

PbootCMS is a content management system used to build and manage websites. A vulnerability in multiple controller files allows attackers to execute arbitrary code on the web server, potentially compromising the entire site and any customer data stored within it. This could lead to data theft, service disruption, malware deployment, or website defacement.

Technical details

The vulnerability exists in multiple controller files (MemberController.php, UserController.php, CommentController.php, ContentController.php) and helper.php in PbootCMS v3.2.15, allowing arbitrary code execution. The exact attack vector and root cause are not fully documented in the available references, but the wide range of affected controller components suggests insufficient input validation or code injection filtering. The attack is likely network-accessible and may not require authentication. Successful exploitation grants the attacker remote code execution on the server with web application privileges, enabling full site compromise. Patching to a version newer than 3.2.15 is the recommended mitigation.

Affected products

  • PbootCMS PbootCMS 3.2.15

Timeline

  • 2026-08-17: disclosed
  • 2026-08-17: advisory

References

Related threats