CVE-2026-21861OS Command Injection in Basercms

Severity
7.2HIGHNVD
EPSS
0.4%
top 41.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31

Description

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server due to improper handling of user-controlled input that is directly passed to exec() without sufficient validation or escaping. This issue has been patched in version 5.2.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages3 packages

NVDbasercms/basercms< 5.2.3
CVEListV5baserproject/basercms< 5.2.3
Packagistbaserproject/basercms< 5.2.3

🔴Vulnerability Details

2
OSV
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)2026-03-31
GHSA
baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)2026-03-31

🕵️Threat Intelligence

1
Wiz
CVE-2026-21861 Impact, Exploitability, and Mitigation Steps | Wiz