LiveActive security incident?Get immediate response
CVE Record

CVE-2026-36239: PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality

PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality

MediumCVSS 4.3Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2026-36239 is reported as a code injection issue in PbootCMS v3.2.11 site configuration functionality. The provided CVSS score is 4.3, indicating moderate severity. Exploitation appears to require high privileges and user interaction, reducing broad attack likelihood. No source in the bundle confirms active exploitation or a vendor patch.

Executive priority

Treat as a moderate-priority issue unless PbootCMS administration is internet-exposed or widely delegated. Prioritize inventory, administrative access control, and vendor update tracking. Escalate if business-critical sites run PbootCMS v3.2.11 or if suspicious configuration changes are found.

Technical view

The record describes a network-reachable vulnerability in PbootCMS v3.2.11 site configuration. CVSS v3.1 vector AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L suggests limited confidentiality, integrity, and availability impact after privileged access and interaction. The CWE listed is CWE-79, which may indicate cross-site scripting, creating ambiguity with the “code injection” title.

Likely exposure

Exposure is likely limited to organizations running PbootCMS v3.2.11, especially where administrative or site configuration functions are accessible to privileged users. The CVE metadata does not provide CPEs or complete affected product data.

Exploitation context

CISA KEV is false in the provided data, and no cited source confirms active exploitation. The CVSS vector indicates attackers need high privileges and user interaction, so this is more concerning for compromised admin accounts or insider-risk scenarios than unauthenticated mass exploitation.

Researcher notes

Evidence is sparse. The title says code injection, while the CVE lists CWE-79. The affected metadata is incomplete, with no CPEs. The only explicit product/version signal is PbootCMS v3.2.11 from the title and description. Avoid assuming exploitability beyond the CVSS vector and cited repository.

Mitigation direction

  • Identify any PbootCMS v3.2.11 deployments.
  • Restrict access to administrative and site configuration functions.
  • Review vendor or project guidance for an official fix.
  • Apply an update if the vendor confirms a patched release.
  • Monitor privileged account activity for unusual configuration changes.

Validation and detection

  • Confirm installed PbootCMS version and exposed admin interfaces.
  • Review site configuration change logs for suspicious entries.
  • Check whether administrative access is limited to trusted networks.
  • Verify least-privilege controls for users with configuration access.
  • Track the CVE record and linked repository for updates.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-79: User-session and phishing behavior lookup

Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-36239 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
4.3 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
2Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
4.3CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L0.93.4CISA-ADP

Vulnerability scoring details

Base CVSS 3.1 score

4.3Medium
CVSS 3.1 vector shape for CVE-2026-36239Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
cvssV3_1other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.