Web::Passwd versions through 0.03 for Perl is vulnerable to RCE.
Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command.
The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection.
Metrics
Affected Vendors & Products
References
History
Thu, 14 May 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 13 May 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection. | |
| Title | Web::Passwd versions through 0.03 for Perl is vulnerable to RCE | |
| Weaknesses | CWE-78 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-05-14T00:35:26.211Z
Reserved: 2026-05-13T20:31:51.641Z
Link: CVE-2026-8500
No data.
Status : Received
Published: 2026-05-13T23:16:43.237
Modified: 2026-05-14T02:17:22.410
Link: CVE-2026-8500
No data.
OpenCVE Enrichment
Updated: 2026-05-13T23:30:06Z