{"schema":"voidly-atlas-federal-record/v1","dataset":"nvd-cves","agency":"NIST","source":"NIST National Vulnerability Database","provider":"Voidly","license":"Source data is U.S. federal public domain (17 U.S.C. §105). Re-surfaced by Voidly under CC BY 4.0.","disclaimer":"This is the agency's own public-domain data, curated and made citable by Voidly. Voidly adds no independent claim — always verify against the linked canonical source.","generated_at":"2026-09-05T12:53:23.921Z","record":{"id":"CVE-2026-8739","cve_id":"CVE-2026-8739","published":"2026-05-17T08:16:23.107","last_modified":"2026-05-17T08:16:23.107","status":"Received","description":"A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigComponent.java. The manipulation of the argument privatefile_key results in use of hard-coded cryptographic key\r . The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss_score":5.3,"cvss_severity":"MEDIUM","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwes":"CWE-320|CWE-321","cpe_count":0,"source_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8739","voidly_url":"https://voidly.ai/atlas/federal/nvd-cves/CVE-2026-8739"},"citation":{"voidly_url":"https://voidly.ai/atlas/federal/nvd-cves/CVE-2026-8739","source_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8739","recommended":"CVE-2026-8739 — MEDIUM. NIST, via Voidly Atlas — Surveillance & Digital-Rights Watch. Retrieved 2026-09-05, https://voidly.ai/atlas/federal/nvd-cves/CVE-2026-8739","ris":"TY  - DATA\nTI  - CVE-2026-8739 — MEDIUM\nAU  - Voidly\nT2  - Voidly Atlas — Surveillance & Digital-Rights Watch\nPB  - Voidly\nPY  - 2026\nUR  - https://voidly.ai/atlas/federal/nvd-cves/CVE-2026-8739\nN1  - Source: NIST National Vulnerability Database, https://nvd.nist.gov/vuln/detail/CVE-2026-8739. Public domain (17 U.S.C. §105); re-surfaced under CC BY 4.0\nER  - ","apa":"Voidly. (2026). CVE-2026-8739 — MEDIUM [NIST National Vulnerability Database]. Voidly Atlas. Retrieved 2026-09-05, from https://voidly.ai/atlas/federal/nvd-cves/CVE-2026-8739","bibtex":"@misc{voidly_nvd_cves_CVE20268739,\n  title        = {CVE-2026-8739 — MEDIUM},\n  author       = {{Voidly}},\n  howpublished = {\\url{https://voidly.ai/atlas/federal/nvd-cves/CVE-2026-8739}},\n  note         = {Source: NIST National Vulnerability Database, https://nvd.nist.gov/vuln/detail/CVE-2026-8739. Public domain (17 U.S.C. §105); re-surfaced under CC BY 4.0},\n  urldate      = {2026-09-05},\n  year         = {2026}\n}"}}