CVE-2026-8500 PUBLISHED

Web::Passwd versions through 0.03 for Perl is vulnerable to RCE

Assigner: CPANSec
Reserved: 13.05.2026 Published: 13.05.2026 Updated: 14.05.2026

Web::Passwd versions through 0.03 for Perl is vulnerable to RCE.

Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command.

The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection.

Product Status

Vendor EVANK
Product Web::Passwd
Versions Default: unaffected
  • affected from 0 to 0.03 (incl.)

Solutions

This application has not been updated since 2007 and appears to have been abandoned. Use other solutions.

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command CWE

Impacts

  • CAPEC-88 OS Command Injection