---
id: CVE-2026-79362
title: Certain Woltlab products are affected by RCE via Cache Poisoning
summary: >-
  Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0
  until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged
  user can inject PHP into executable cache files generated by WoltLab Suite
  Core…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
published: '2026-09-11'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:00:03.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79362'
references:
  - url: >-
      https://github.com/WoltLab/WCF/commit/c19789dbcc15663c648db1b196b6e6b05265b121
    label: cve@mitre.org
  - url: >-
      https://www.woltlab.com/community/thread/319263-update-woltlab-suite-6-2-6-6-1-23/
    label: cve@mitre.org
  - url: >-
      https://www.woltlab.com/community/thread/319264-aktualisierung-woltlab-suite-6-2-6-6-1-23/
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
epss: 0.00433
epssPercentile: 0.37164
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-21T16:01:51.858181Z'
ingestedAt: '2026-09-14T00:35:28.535Z'
---

## Overview

Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
