« Volver al listado

CVE-2026-52778

Estado: AplazadaCrítica (9.8)—

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The application attempts to sanitize user-defined mathematical formulas using a complex recursive regular expression before passing them to the PHP eval() function. This implementation is inherently flawed: it is vulnerable to Regular Expression Denial of Service (ReDoS / Stack Overflow) which can crash the server, and it creates a high-risk architecture where any logic bypass directly results in arbitrary PHP code execution. Version 4.6.6 patches the issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso remoto sin autenticación (AV:N/PR:N) a PHP eval() en campo calculador de formulario Bazar. ReDoS causa DoS; bypass de regex sanitizador permite ejecución de código PHP arbitrario.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-52778",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-52778",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-09T15:54:35.483833Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "YesWiki",
          "product": "yeswiki",
          "versions": [
            {
              "status": "affected",
              "version": "< 4.6.6"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-08T19:16:46.683",
  "references": [
    {
      "url": "https://github.com/YesWiki/yeswiki/commit/dd2bd8fb099de0d21504bda8a810693b3fcb8e52",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/YesWiki/yeswiki/security/advisories/GHSA-px5m-h76g-p7p8",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/YesWiki/yeswiki/security/advisories/GHSA-px5m-h76g-p7p8",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        },
        {
          "lang": "en",
          "value": "CWE-1333"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The application attempts to sanitize user-defined mathematical formulas using a complex recursive regular expression before passing them to the PHP eval() function. This implementation is inherently flawed: it is vulnerable to Regular Expression Denial of Service (ReDoS / Stack Overflow) which can crash the server, and it creates a high-risk architecture where any logic bypass directly results in arbitrary PHP code execution. Version 4.6.6 patches the issue."
    },
    {
      "lang": "es",
      "value": "YesWiki es un sistema wiki escrito en PHP. Antes de la versión 4.6.6, existe una vulnerabilidad de ejecución insegura en la calculadora de campos de formulario Bazar (CalcField.php) de YesWiki. La aplicación intenta sanear fórmulas matemáticas definidas por el usuario utilizando una expresión regular recursiva compleja antes de pasarlas a la función PHP eval(). Esta implementación es inherentemente defectuosa: es vulnerable a la denegación de servicio por expresión regular (ReDoS / desbordamiento de pila) lo que puede bloquear el servidor, y crea una arquitectura de alto riesgo donde cualquier omisión de lógica resulta directamente en la ejecución arbitraria de código PHP. La versión 4.6.6 corrige el problema."
    }
  ],
  "lastModified": "2026-07-23T08:10:00.137",
  "sourceIdentifier": "security-advisories@github.com"
}