Contao Managed Edition v1.5.0 contains a remote command execution vulnerability due to improper handling of the php_cli parameter. An attacker can exploit this flaw to execute arbitrary commands on the server by manipulating the php_cli parameter.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Python proof-of-concept/operational exploit for CVE-2022-26265 targeting Contao CMS 1.5.0. It contains only two files: a README with usage instructions and main.py with the exploit logic. The code is part of the author's 'hgrab-framework', but not a mainstream exploit framework; analysis is focused on the single exploit script. The exploit reads a list of target base URLs from a file and a command from the command line, then spawns a thread per target. For each host, it sends an HTTP POST request to /api/server/config with JSON data setting php_cli to the attacker-supplied command and cloud to false. The request includes headers typical of an AJAX/API call, notably X-Requested-With and X-HTTP-Method-Override: PUT, and uses a hardcoded contao_manager_auth JWT cookie to appear authenticated. The intended capability is remote command execution through malicious modification of server configuration. Notable operational characteristics: the payload is customizable at runtime via the second CLI argument; the exploit is multi-target and multi-threaded; there is no built-in verification, shell management, or post-exploitation logic beyond printing the HTTP status code and response body. The script does not include target discovery or vulnerability detection, so it is an exploitation utility rather than a scanner. The main fingerprintable target endpoint is /api/server/config, and the hardcoded cookie name contao_manager_auth is a useful indicator for detection or hunting.
This repository is an exploit for CVE-2022-26265, targeting Contao CMS v1.5.0. It is part of the hgrab-framework. The exploit is implemented in Python (main.py) and is designed to achieve remote code execution (RCE) on vulnerable Contao CMS installations. The user supplies a file containing a list of target URLs and a command to execute. For each target, the script sends a specially crafted POST request to the /api/server/config endpoint, attempting to execute the supplied command via the 'php_cli' parameter. The exploit uses multithreading to attack multiple targets concurrently. The README provides usage instructions and describes the required input format. The main fingerprintable endpoint is /api/server/config, and the exploit is operational, providing real RCE if the target is vulnerable.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.