Redeight CMS 1.0 hit by three flaws
CERT Polska disclosed three vulnerabilities in Redeight CMS 1.0, including an unauthenticated SQL injection and an authenticated RCE via file upload.
CERT Polska coordinated disclosure of three vulnerabilities affecting Redeight CMS version 1.0. The most severe, CVE-2026-53690, is an unauthenticated SQL injection in the admin login endpoint's userEmail parameter, caused by direct interpolation of user input into SQL queries without prepared statements, allowing remote attackers to extract database contents without credentials.
CVE-2026-53691 is an unrestricted file upload vulnerability in the authenticated admin panel's page management module, which fails to validate file extensions or MIME types, enabling authenticated attackers to upload and execute arbitrary PHP scripts from a publicly accessible uploads directory, resulting in remote code execution. CVE-2026-53692 compounds the risk by revealing that the CMS stores passwords using unsalted MD5 hashes, a cryptographically weak scheme that is trivially reversible via rainbow tables, meaning any hash exposure (e.g., via the SQLi) would likely lead to full credential compromise.
No evidence of in-the-wild exploitation is mentioned; this is a coordinated disclosure following a report from an external researcher. Organizations running Redeight CMS 1.0 should patch or mitigate these issues, particularly the unauthenticated SQL injection, which combined with the weak password hashing significantly lowers the bar for full compromise.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-53690
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free