


Perceptive Security
SOC/SIEM Consultancy

Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor that allows low-privilege authenticated user…
Published:
5 May 2026 at 22:00:00
Alert date:
6 May 2026 at 20:01:39
Source:
nvd.nist.gov
Web Technologies
Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor. The vulnerability allows low-privilege authenticated users (editor, author, contributor, or site_admin roles) to execute arbitrary code by exploiting insufficient file extension restrictions. Attackers can write a malicious .htaccess file to map arbitrary extensions to the PHP handler, then upload PHP code with that extension. This can lead to unauthenticated remote code execution when the malicious file is accessed via HTTP. The vulnerability affects the admin code editor component and has been addressed in version 1.0.8.2.
Technical details
Mitigation steps:
Affected products:
Vvveb
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41934
https://github.com/givanz/Vvveb/commit/1196561276a3f49da5a714fef89ac9a6c6f9e33b
https://github.com/givanz/Vvveb/releases/tag/1.0.8.2
https://github.com/givanz/Vvveb/security/advisories/GHSA-vfjj-gcvv-w248
https://www.vulncheck.com/advisories/vvveb-authenticated-rce-via-code-editor
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
