« Volver al listado

CVE-2026-39850

Estado: AplazadaAlta (7.4)—

Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local File Inclusion. The function calls extract($_params_, EXTR_OVERWRITE) before the require statement that loads the view file. As a result, a caller-controlled _file_ key in the $params array overwrites the internal local variable specifying which file to include, potentially enabling RCE if an attacker can write PHP files through a separate primitive, as well as information disclosure. This issue has been fixed in version 2.0.55.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad en aplicación web expuesta (Yii framework) accesible por red sin autenticación. LFI + RCE potencial si el atacante controla parámetros y puede escribir ficheros PHP; impactos: lectura de ficheros y ejecución de código.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-39850",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-39850",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-21T03:55:53.898116Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.4,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "yiisoft",
          "product": "yii2",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.0.55"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-20T20:16:39.850",
  "references": [
    {
      "url": "https://github.com/yiisoft/yii2/commit/109878b491dbffa541032bc99fb5e26d12cd0375",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/yiisoft/yii2/security/advisories/GHSA-5vpg-rj7q-qpw2",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        },
        {
          "lang": "en",
          "value": "CWE-98"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local File Inclusion. The function calls extract($_params_, EXTR_OVERWRITE) before the require statement that loads the view file. As a result, a caller-controlled _file_ key in the $params array overwrites the internal local variable specifying which file to include, potentially enabling RCE if an attacker can write PHP files through a separate primitive, as well as information disclosure. This issue has been fixed in version 2.0.55."
    },
    {
      "lang": "es",
      "value": "Yii 2 es un framework de aplicación PHP. Las versiones 2.0.54 y anteriores contienen lógica defectuosa en el método central de renderizado de vistas View::renderPhpFile() que conduce a una inclusión local de ficheros. La función llama a extract($_params_, EXTR_OVERWRITE) antes de la sentencia require que carga el fichero de vista. Como resultado, una clave _file_ controlada por el llamador en el array $params sobrescribe la variable local interna que especifica qué fichero incluir, lo que podría habilitar RCE si un atacante puede escribir ficheros PHP a través de una primitiva separada, así como revelación de información. Este problema ha sido corregido en la versión 2.0.55."
    }
  ],
  "lastModified": "2026-07-23T12:10:00.110",
  "sourceIdentifier": "security-advisories@github.com"
}