Executive brief
Diem is a content management framework for PHP projects. The administrative console feature contains a command execution vulnerability that allows authenticated administrators to bypass intended command restrictions and run arbitrary system commands with the privileges of the web server process, potentially leading to unauthorized access to sensitive data or system compromise.
Technical details
The vulnerability is an OS command injection in dmAdminPlugin/modules/dmConsole/actions/actions.class.php. The executeCommand function validates only the first space-delimited token of user input against an allowlist of permitted commands (such as "ls"), then passes the entire unvalidated input string to the shell via passthru(). An attacker can bypass this by appending shell metacharacters (e.g., "ls ; id #") after an allowed command, with comment characters masking appended options. The attack requires authentication with administrative console privileges and network access to the admin interface. An attacker can execute arbitrary OS commands with the privileges of the PHP/web-server process, potentially accessing configuration files, credentials, or taking over the application host. The vulnerability was reported on 2026-07-17, a public proof-of-concept exists, and the project had not provided a patch as of the advisory date.
Affected products
- diem-project Diem up to 5.1.3
Timeline
- 2026-07-17: disclosed: Issue reported via GitHub #447
- 2026-08-31: advisory: CVE-2026-82678 published
- 2026-07-17: other: Public exploit available; project did not respond to early notification