CVE-2026-29014

CRITICAL EXPLOITED NUCLEI

MetInfo CMS 7.9-8.1 - Unauthenticated PHP Code Injection

Title source: manual
STIX 2.1

Exploitation Summary

CVE-2026-29014 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including HORKimhab. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains a placeholder markdown file for CVE-2026-29014, describing an unauthenticated PHP code injection RCE in MetInfo CMS versions 7.9, 8.0, and 8.1. However, no actual exploit code, technical details, or proof-of-concept implementation is provided.

Description

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.

Exploits (1)

github STUB
by HORKimhab · shellpoc
https://github.com/HORKimhab/poc-cve-collection/tree/main/2026/29xxx/CVE-2026-29014.md

The repository contains a placeholder markdown file for CVE-2026-29014, describing an unauthenticated PHP code injection RCE in MetInfo CMS versions 7.9, 8.0, and 8.1. However, no actual exploit code, technical details, or proof-of-concept implementation is provided.

Classification
Stub 95%
Attack Type
Rce
Complexity
Unknown
Reliability
Theoretical
Target: MetInfo CMS versions 7.9, 8.0, and 8.1
No auth needed
Prerequisites: Access to a vulnerable MetInfo CMS instance
mistral-large-3 · analyzed Jul 14, 2026 Full analysis →

Nuclei Templates (1)

MetInfo CMS <= 8.1 - Remote Code Execution
CRITICALVERIFIEDby 0x_Akoko
Shodan: http.title:"MetInfo"
FOFA: app="MetInfo"

Scores

CVSS v3 9.8
EPSS 0.4158
EPSS Percentile 98.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-04-25
CWE
CWE-94
Status published
Products (4)
metinfo/metinfo 7.9
metinfo/metinfo 8.0.0
metinfo/metinfo 8.1
MetInfo CMS/MetInfo CMS 7.9.0 - 8.1.0
Published Apr 01, 2026
Tracked Since Apr 01, 2026