HomeSecurityMetInfo CMS vulnerability exploited for RCE attacks

MetInfo CMS vulnerability exploited for RCE attacks

Malicious users are actively exploiting a critical security vulnerability affecting an open-source content management system (CMS) known as MetInfo, according to new discoveries from VulnCheck.

See also: Apache MINA: Vulnerabilities allow RCE attacks

MetInfo

The vulnerability being investigated is CVE-2026-29014 (CVSS score: 9.8), a code injection vulnerability that could lead to arbitrary code execution. NIST’s National Vulnerability Database (NVD) states that “versions 7.9, 8.0, and 8.1 of MetInfo CMS contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code.”

“Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain complete control over the affected server.”

Security researcher Egidio Romano, who discovered the vulnerability, noted that the issue is rooted in the “/app/system/weixin/include/class/weixinreply.class.php” script and stems from a lack of adequate sanitization of input provided by users when issuing Weixin (aka WeChat) API requests. As a result, remote, unauthenticated attackers could exploit this gap to inject and execute arbitrary PHP code.

See also: GitHub fixed critical RCE vulnerability in less than 6 hours

MetInfo CMS vulnerability exploited for RCE attacks

A key prerequisite for successful exploitation when MetInfo is running on non-Windows servers is that the “/cache/weixin/” directory must exist in advance. This directory is created during the installation and configuration of the official WeChat plugin.

Patches for CVE-2026-29014 were released by MetInfo on April 7, 2026. The vulnerability has been exploited since April 25, with a “small number of exploits” deployed against vulnerable honeypots located in the U.S. and Singapore. While these efforts were initially sparse and linked to automated detections, activity spiked on May 1, 2026, focusing on IP addresses from China and Hong Kong, according to Caitlin Condon, vice president of security research at VulnCheck. As many as 2,000 instances of MetInfo CMS are accessible online, most of which are located in China.

This vulnerability highlights the importance of promptly applying security patches and continuously monitoring systems for potential threats. System administrators using MetInfo CMS are urged to immediately update their installations and ensure that their servers are protected from such attacks. The lack of adequate input sanitization and the possibility of arbitrary code execution make this vulnerability particularly dangerous, especially for organizations that rely on this CMS to manage their online content.

See also: Critical bug in Cursor turns Git routine into RCE

MetInfo CMS vulnerability exploited for RCE attacks

VulnCheck continues to monitor the situation and provide updates regarding the exploitation of the vulnerability, while MetInfo CMS users are encouraged to stay informed of the latest developments and take the necessary measures to protect their systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS