A vulnerability was found in baserproject basercms up to 5.2.2. It has been declared as critical. This affects the function exec. The manipulation results in os command injection. This vulnerability was named CVE-2026-21861. The attack may be performed from remote. There is no available exploit. It is recommended to upgrade the affected component.
| Vendor | Product | Versions |
|---|---|---|
| baserproject | basercms | < 5.2.3, 5.2.2 |
Updated affected versions to include 5.2.2, confirmed severity as CRITICAL, and noted that there is no available exploit.
Initial creation