CVE-2026-38615: OS Command Injection
DedeCMS V5.7.118 is vulnerable to Command Execution in filemanagecontrol.php.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
DedeCMS v5.7.118from your environment.Uninstall or remove DedeCMS v5.7.118 from affected hosts or take the site offline until a vendor-supplied patch/fixed release is available.
- Configuration
Remove or deny external web access to file_manage_control.php (for example, delete the file or add webserver rules to return 403/deny for requests to this file) until a vendor fix is provided.
DedeCMS (file_manage_control.php) web access to file_manage_control.php = disabled - Compensating control
Restrict access to management interfaces and the file_manage_control.php endpoint to trusted IP addresses using network controls (firewall, ACLs), a WAF, or reverse proxy; block public internet access to these endpoints until patched.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-38615?
CVE-2026-38615 has a critical severity rating of 9.8.
What kind of vulnerability is CVE-2026-38615?
CVE-2026-38615 is an OS Command Injection vulnerability.
How do I fix CVE-2026-38615?
To fix CVE-2026-38615, it is recommended to update DedeCMS to a version that addresses this vulnerability.
What software is affected by CVE-2026-38615?
CVE-2026-38615 affects DedeCMS version 5.7.118.
When was CVE-2026-38615 published?
CVE-2026-38615 was published on June 9, 2026.