216.73.217.22

CVE-2026-8500

· Published 13/05/2026 23:16 · Modified 14/05/2026 18:16

Labels: CVE-2026-8500 2026-05-139b29abf9-4ab0-4765-b253-1875cd9b441eCVE-2026-8500CWE-78

Essential information

Published
13/05/2026 23:16
Modified
14/05/2026 18:16
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
9b29abf9-4ab0-4765-b253-1875cd9b441e
NVD
View on NVD

Affected products (CPE)

ProductCPE
perl / web cpe:2.3:a:perl:web::passwd:*:*:*:*:*:*:*:*

References