CVE-2026-3786 is a remote SQL injection vulnerability affecting EasyCMS up to version 1.6. The issue is reported in an unknown function within /RbacuserAction.class.php, specifically in the request parameter handling logic. An attacker can manipulate the _order argument to inject arbitrary SQL into backend database queries. The vulnerable condition stems from insufficient neutralization of attacker-controlled input before it is incorporated into SQL statements. Public exploit information is available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python exploit script (exploit.py) and a minimal README referencing CVE-2026-3786. The script is a multi-threaded network scanner/exploit tool targeting a web admin endpoint at /index.php?s=/admin/rbacuser/index. It first performs a time-based SQL injection check by POSTing form data with an injected _order parameter using sleep(5) and measuring response delay. If vulnerable, it escalates to attempted OS command execution by appending ';<cmd>' (e.g., id, uname -a) after a benign SQL fragment, then heuristically searches the HTTP response for command output indicators (uid=, linux, etc.). It also attempts to retrieve the database name by executing 'cat' against a list of common configuration file paths (ThinkPHP/WordPress/Joomla/Drupal) and regex-parsing the response for DB name patterns. Finally, it attempts to write a PHP eval webshell to the target web root as css.php by echoing hex-encoded PHP content via the same injection vector, then verifies by requesting /css.php and checking for 'eval' in the response. Results are logged locally to vuln.txt, rce.txt, and shells.txt; targets are supplied via a positional argument or a targets.txt file, with configurable thread count.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.