CVE-2026-90708: Yot CMS Cookie global.php login sql injection

Published Sep 14, 2026
·
Updated

A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file global.php of the component Cookie Handler. This manipulation of the argument yot3user/yot3pass causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

Affected Software

1 affected component
Yot CMS<=3.3.1

Event History

Sep 14, 2026
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments should be considered exposed?

Yot CMS deployments running version 3.3.1 or earlier should be considered affected. The vulnerable login handling is in global.php's Cookie Handler component.

2

Does an attacker need an account or user interaction to exploit this issue?

No. The supplied vector indicates remote exploitation with low attack complexity, no privileges, and no user interaction required. The attacker manipulates the yot3_user and yot3_pass arguments.

3

How urgent is remediation?

Remediation should be prioritized because a public exploit is available and the issue can be attacked remotely without authentication. The reported impact includes partial compromise of confidentiality, integrity, and availability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203