CVE-2026-53690

CRITICAL

SQL Injection in Redeight CMS

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-53690. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-53690, an SQL Injection vulnerability in Redeight CMS 1.0 via the 'userEmail' parameter in the admin login endpoint. The code includes placeholder methods (`check`, `run`) but lacks actual exploit implementation or payload delivery.

Description

An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/index.php" login endpoint. The application fails to sanitize user input and directly interpolates it into SQL queries without using prepared statements, which allows unauthenticated remote attackers to execute arbitrary SQL commands and extract sensitive database information.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-53690_sql_injection_vulnerability.py

This repository contains an auto-generated stub module for CVE-2026-53690, an SQL Injection vulnerability in Redeight CMS 1.0 via the 'userEmail' parameter in the admin login endpoint. The code includes placeholder methods (`check`, `run`) but lacks actual exploit implementation or payload delivery.

Classification
Stub 98%
Attack Type
Sqli
Complexity
Moderate
Reliability
Theoretical
Target: Redeight CMS version 1.0
No auth needed
Prerequisites: Network access to the target's admin login endpoint (/admin/index.php) · Redeight CMS 1.0 deployment
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory third-party-advisory
https://cert.pl/posts/2026/06/CVE-2026-53690

Scores

CVSS v4 9.3
EPSS 0.0040
EPSS Percentile 32.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
Redeight/Redeight CMS 1.0
Published Jun 30, 2026
Tracked Since Jun 30, 2026