Junglewise Threat Intelligence

CVE-2026-86182: Diem CMF cross-site request forgery in admin console

CVE-2026-86182 · Severity: medium · CVSS 4.3 · Published 2026-09-06

Technologies: Diem-Project Diem. Vendors: Diem-Project.

Executive brief

Diem is a content management framework for PHP that provides administrative functionality for managing website content. A vulnerability in the administrative console allows an attacker to trick a logged-in administrator into executing arbitrary commands on the web server by opening a specially crafted link, potentially leading to data theft, unauthorized modifications, and server compromise.

Technical details

The vulnerability is a cross-site request forgery (CSRF) in the dmConsole module's executeCommand action. The root cause is that the administrative plugin globally disables Symfony's CSRF protection (sfConfig::add(['sf_csrf_secret' => false]) and the executeCommand function accepts the privileged dm_command parameter via GET without validating a CSRF token or enforcing POST-only requests. An attacker can craft a malicious web page that uses client-side redirection to navigate an authenticated administrator's browser to the vulnerable endpoint, causing arbitrary command execution in the web server's security context. The attack requires no authentication and only user interaction (opening a link), and the vulnerable code path executes system commands with the privileges of the PHP/web-server process.

Affected products

  • diem-project Diem up to 5.1.3

Timeline

  • 2026-07-19: disclosed: Issue #449 opened on GitHub
  • 2026-09-06: advisory: CVE-2026-86182 published

References

Related threats