
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32276 is a code injection vulnerability in Connect-CMS, an open-source content management system developed by opensource-workshop, that allows authenticated users to execute arbitrary code via the Code Study Plugin. It affects all 1.x series versions up to and including 1.41.0 and all 2.x series versions up to and including 2.41.0. The vulnerability was disclosed on March 23, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.8 (High) (Github Advisory, Security Advisory).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection): the Code Study Plugin fails to properly neutralize user-supplied input before incorporating it into executable code segments, allowing an authenticated user to inject and execute arbitrary code on the server. The attack vector is network-based, requires low privileges (a valid authenticated session), no user interaction, and low attack complexity. The fix, committed as c0bcd07, involved removing the vulnerable Codestudies model and plugin entirely, along with associated database migrations and views, suggesting the plugin's design was fundamentally unsafe (Security Advisory, Patch Commit).
Successful exploitation grants an authenticated attacker the ability to execute arbitrary code on the server hosting Connect-CMS, resulting in high impact to confidentiality, integrity, and availability. An attacker could exfiltrate sensitive data stored in the CMS (including user credentials and content), modify or delete critical information, install backdoors or web shells for persistent access, and potentially disrupt service availability entirely. The vulnerability could also serve as a pivot point for lateral movement within the hosting environment (Github Advisory, Security Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Github Advisory). The EPSS score is approximately 0.103% (28th percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The requirement for a valid authenticated session limits the attack surface compared to unauthenticated vulnerabilities, though insider threats or compromised accounts remain a realistic risk vector.
app/Models/User/Codestudies/, Plugins/User/Codestudies/) on unpatched systems.bash, sh, curl, wget, python) that are not part of normal CMS operation.The primary remediation is to upgrade Connect-CMS to version 1.41.1 (for the 1.x series) or 2.41.1 (for the 2.x series), both released on March 23, 2026. The patch removes the vulnerable Code Study Plugin entirely rather than attempting to sanitize its input. No configuration-based workaround is documented; if immediate patching is not possible, administrators should restrict access to the Code Study Plugin functionality and review user account permissions to limit exposure to trusted users only (Security Advisory, v1.41.1 Release, v2.41.1 Release).
The vulnerability was reported by Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc., who was credited in the official advisory (Security Advisory). The disclosure received limited but notable coverage from security news aggregators and automated CVE tracking accounts on platforms such as Mastodon and Bluesky shortly after publication. No major vendor statements or significant community debate beyond standard vulnerability tracking have been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."