Executive brief
Sanluan PublicCMS, a content management system, contains a security flaw in how it protects private files. The system uses a predictable, hard-coded method to generate security keys for file access instead of using unique, random secrets. An attacker can exploit this to bypass security controls and download private documents or sensitive images without needing to log in.
Technical details
A cryptographic design flaw exists in the SafeConfigComponent.getSignKey function of Sanluan PublicCMS 5.202506.d. The application uses a deterministic fallback value for the 'privatefile_key' when it is not explicitly configured. This key is derived from predictable inputs, including the site ID and a cluster identifier that is publicly exposed via the '/api/directive/tools/version' endpoint. An unauthenticated remote attacker can obtain these inputs, derive the signing key offline, and forge valid signatures for the '/file/private' endpoint. This allows for the unauthorized download of any private file if the file path is known. The vendor has reportedly not responded to disclosure attempts.
Affected products
- Sanluan PublicCMS 5.202506.d
Timeline
- 2026-05-17: advisory: CVE-2026-8739 published via NVD/VulDB
- 2026-05-17: disclosed: Exploit code and technical analysis made public