CVE-2022-26265

CRITICAL

Contao Managed Edition <1.5.0 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2022-26265. PoCs published by SystemVll, redteamsecurity2023.

AI-analyzed exploit summary This repository contains a Python-based exploit for CVE-2022-26265, targeting Contao CMS v1.5.0. The exploit sends a crafted POST request to the `/api/server/config` endpoint with a malicious `php_cli` parameter to achieve remote code execution (RCE).

Description

Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.

Exploits (3)

nomisec WORKING POC 10 stars
by SystemVll · poc
https://github.com/SystemVll/CVE-2022-26265

This repository contains a Python-based exploit for CVE-2022-26265, targeting Contao CMS v1.5.0. The exploit sends a crafted POST request to the `/api/server/config` endpoint with a malicious `php_cli` parameter to achieve remote code execution (RCE).

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Contao CMS v1.5.0
Auth required
Prerequisites: Target must be running Contao CMS v1.5.0 · Valid authentication cookie (`contao_manager_auth`)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by redteamsecurity2023 · poc
https://github.com/redteamsecurity2023/CVE-2022-26265

This PoC exploits CVE-2022-26265, an RCE vulnerability in Contao CMS v1.5.0, by sending a crafted POST request to the `/api/server/config` endpoint with a malicious `php_cli` parameter. The exploit uses a hardcoded JWT token for authentication and supports multi-threaded execution against a list of targets.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Contao CMS v1.5.0
Auth required
Prerequisites: Target running Contao CMS v1.5.0 · Valid JWT token (hardcoded in the exploit)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
inthewild WORKING POC
poc
https://github.com/inplex-sys/cve-2022-26265

This repository contains a functional exploit for CVE-2022-26265, targeting Contao CMS v1.5.0. The exploit sends a crafted POST request to the `/api/server/config` endpoint with a malicious `php_cli` parameter to achieve remote code execution (RCE).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Contao CMS v1.5.0
Auth required
Prerequisites: Valid Contao CMS v1.5.0 instance · Authentication cookie (`contao_manager_auth`)
devstral-2 · analyzed Feb 23, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.7154
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
contao/contao 1.5.0
contao/managed-edition 0Packagist
Published Mar 18, 2022
Tracked Since Feb 18, 2026