An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server. NOTE: the Supplier's position is that this is "a historical and intended administrative feature of the product, accessible only to already authenticated users explicitly granted administrator privileges." However, restrictions on some PHP functions were added in 8.4.
History

Mon, 27 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Title Administrative RCE via Arbitrary PHP Execution in Kiamo <8.4

Wed, 22 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server. An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server. NOTE: the Supplier's position is that this is "a historical and intended administrative feature of the product, accessible only to already authenticated users explicitly granted administrator privileges." However, restrictions on some PHP functions were added in 8.4.

Wed, 15 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Title Authenticated Admin Arbitrary PHP Code Execution in Kiamo Prior to v8.4

Tue, 14 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Apr 2026 10:00:00 +0000

Type Values Removed Values Added
Title Authenticated Admin Arbitrary PHP Code Execution in Kiamo Prior to v8.4

Fri, 10 Apr 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Kiamo
Kiamo kiamo
Vendors & Products Kiamo
Kiamo kiamo

Thu, 09 Apr 2026 16:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-04-09T00:00:00.000Z

Updated: 2026-04-22T14:47:51.482Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-70364

cve-icon Vulnrichment

Updated: 2026-04-14T14:51:55.015Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-09T16:16:25.573

Modified: 2026-04-22T15:16:12.357

Link: CVE-2025-70364

cve-icon Redhat

No data.