---
id: CVE-2026-90709
title: A security vulnerability has been detected in Yot CMS up to 3.3.1
summary: >-
  A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by
  this issue is the function eval of the file modsys/console/admin.php of the
  component Admin Console. Such manipulation of the argument text leads to code
  inje…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-94
vendor: Yot
product: CMS
affected:
  - CMS 3.3.0
  - CMS 3.3.1
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:56:48.220'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90709'
references:
  - url: >-
      https://github.com/dddwmr/CVE/blob/main/YOT%20III%20modsys%3Aconsole%20admin%20eval%20of%20POST%20text%20leads%20to%20remote%20code%20execution.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90709'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/918371'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403251'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403251/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T11:41:07.251734Z'
ingestedAt: '2026-09-14T15:23:07.460Z'
epss: 0.00412
epssPercentile: 0.32633
---

## Overview

A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
