CVE-2026-8739: Sanluan PublicCMS SafeConfigComponent.java getSignKey hard-coded key
A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigComponent.java. The manipulation of the argument privatefilekey results in use of hard-coded cryptographic key . The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8739?
CVE-2026-8739 has been identified as a high severity vulnerability due to its potential for exposing sensitive information through hard-coded keys.
How do I fix CVE-2026-8739?
To fix CVE-2026-8739, update the Sanluan PublicCMS to the latest version where the hard-coded key issue has been resolved.
What component is affected by CVE-2026-8739?
CVE-2026-8739 affects the getSignKey method in the SafeConfigComponent class of Sanluan PublicCMS.
Who is affected by CVE-2026-8739?
Any user or organization running Sanluan PublicCMS version 5.202506.d is affected by CVE-2026-8739.
What is the attack vector for CVE-2026-8739?
The attack vector for CVE-2026-8739 involves exploiting the hard-coded key to potentially compromise system security.