CVE-2026-29909: Mrcms

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.

Affected products

  • Mrcms Mrcms: version 3.1.2 only

Published 2026-03-30. Last modified 2026-06-17.