CVE-2026-79362

Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code.

  • Published Sep 11, 2026
  • CVSS 8.8 high
  • 0.6% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

CVE-2026-79362 at the National Vulnerability Database