


Perceptive Security
SOC/SIEM Consultancy

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0,…
Published:
7 april 2026 om 22:00:00
Alert date:
8 april 2026 om 16:01:27
Source:
nvd.nist.gov
Web Technologies
CI4MS, a CodeIgniter 4-based CMS skeleton, contains a critical vulnerability in versions prior to 0.31.4.0. The install route guard relies solely on volatile cache checks and .env file existence to prevent post-installation access to the setup wizard. When the database becomes temporarily unreachable during cache misses (TTL expiry or admin-triggered cache clear), the security guard fails open. This allows unauthenticated attackers to overwrite the .env file with malicious database credentials, resulting in complete application takeover. The vulnerability has been patched in version 0.31.4.0.
Technical details
Mitigation steps:
Affected products:
CI4MS
CodeIgniter 4
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-39393
https://github.com/ci4-cms-erp/ci4ms/security/advisories/GHSA-8rh5-4mvx-xj7j
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
