MetInfo CMS Vulnerability CVE-2026-29014 Exploited in Wild

What happened

CVE-2026-29014, a code injection vulnerability with a CVSS score of 9.8, has been discovered in MetInfo CMS versions 7.9, 8.0, and 8.1. This flaw allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code.

Technical details

The vulnerability is rooted in the “/app/system/weixin/include/class/weixinreply.class.php” script and stems from a lack of adequate sanitization of user-supplied input when issuing Weixin (aka WeChat) API requests. To exploit this vulnerability, attackers need to inject and execute arbitrary PHP code. On non-Windows servers, the “/cache/weixin/” directory must exist beforehand, which is created when installing and configuring the official WeChat plugin.

Exploitation and patches

Patches for CVE-2026-29014 were released by MetInfo on April 7, 2026. However, the vulnerability has since come under exploitation as of April 25, with a “small number of exploits” deployed against susceptible honeypots located in the U.S. and Singapore. The activity witnessed a surge on May 1, 2026, focusing on China and Hong Kong IP addresses.

Detection guidance

Defenders should immediately patch MetInfo CMS to the latest version and verify that the “/cache/weixin/” directory is properly secured. Additionally, monitor for suspicious activity related to the Weixin API requests and arbitrary PHP code execution.

Warning: As many as 2,000 instances of MetInfo CMS are accessible online, most of which are in China, making them potential targets for exploitation.

Leave a Comment

Your email address will not be published. Required fields are marked *