What happened
CVE-2026-29014, a code injection vulnerability with a CVSS score of 9.8, has been discovered in MetInfo CMS versions 7.9, 8.0, and 8.1. This flaw allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code.
Technical details
The vulnerability is rooted in the “/app/system/weixin/include/class/weixinreply.class.php” script and stems from a lack of adequate sanitization of user-supplied input when issuing Weixin (aka WeChat) API requests. To exploit this vulnerability, attackers need to inject and execute arbitrary PHP code. On non-Windows servers, the “/cache/weixin/” directory must exist beforehand, which is created when installing and configuring the official WeChat plugin.
Exploitation and patches
Patches for CVE-2026-29014 were released by MetInfo on April 7, 2026. However, the vulnerability has since come under exploitation as of April 25, with a “small number of exploits” deployed against susceptible honeypots located in the U.S. and Singapore. The activity witnessed a surge on May 1, 2026, focusing on China and Hong Kong IP addresses.
Detection guidance
Defenders should immediately patch MetInfo CMS to the latest version and verify that the “/cache/weixin/” directory is properly secured. Additionally, monitor for suspicious activity related to the Weixin API requests and arbitrary PHP code execution.
Warning: As many as 2,000 instances of MetInfo CMS are accessible online, most of which are in China, making them potential targets for exploitation.
