CVE-2026-32276
HIGHConnect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
Title source: cnaDescription
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an authenticated user may be able to execute arbitrary code in the Code Study Plugin. Versions 1.41.1 and 2.41.1 contain a patch.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/opensource-workshop/connect-cms/security/advisories/GHSA-hxqw-6qv7-cqfv
X_Refsource_Misc x_refsource_misc
https://github.com/opensource-workshop/connect-cms/commit/c0bcd07fc1e9375941aa1295d044328ecd44ed85
X_Refsource_Misc x_refsource_misc
https://github.com/opensource-workshop/connect-cms/releases/tag/v1.41.1
X_Refsource_Misc x_refsource_misc
https://github.com/opensource-workshop/connect-cms/releases/tag/v2.41.1
Scores
CVSS v3
8.8
EPSS
0.0046
EPSS Percentile
36.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (4)
opensource-workshop/connect-cms
0 - 1.41.1Packagist
opensource-workshop/connect-cms
1.0.0 - 1.41.1
opensource-workshop/connect-cms
< 1.41.1
opensource-workshop/connect-cms
>= 2.0.0, < 2.41.1
Published
Mar 23, 2026
Tracked Since
Mar 24, 2026