Response playbooks, investigation guides, and Atomic Red Team tests are Pro-only. Upgrade to unlock the full detection package for CVE-2026-52778.

Upgrade to Pro
CVE-2026-52778 Google Chronicle · YARA-L

Detect YesWiki Formula Calculator Unsafe eval() Remote Code Execution (CVE-2026-52778) in Google Chronicle

YesWiki prior to 4.6.6 exposes an unsafe PHP eval() call in its Formula Calculator feature (BazaR calculated field logic). An unauthenticated or low-privileged attacker can craft a malicious formula expression that is passed directly into eval(), resulting in arbitrary PHP code execution on the underlying web server, or a crafted expression that triggers resource exhaustion / infinite loops causing denial of service. Successful exploitation grants the attacker the privileges of the web server process, enabling webshell deployment, credential theft, and lateral movement.

MITRE ATT&CK

Tactic
Initial Access Execution Impact

YARA-L Detection Query

Google Chronicle (YARA-L)
yaral
rule yeswiki_formula_eval_rce
{
  meta:
    author = "df00tech"
    description = "Detects exploitation attempts against YesWiki CVE-2026-52778 unsafe eval() in Formula Calculator"
    severity = "CRITICAL"

  events:
    $http.metadata.event_type = "NETWORK_HTTP"
    $http.target.url = /(BF_formula|BazaR|formulaire)/ nocase
    $http.target.url = /(eval\(|system\(|exec\(|base64_decode|shell_exec)/ nocase

  condition:
    $http
}
critical severity medium confidence

Chronicle YARA-L rule detecting HTTP requests to YesWiki formula endpoints containing embedded PHP code execution primitives, matching CVE-2026-52778 exploitation patterns.

Data Sources

Chronicle Web Proxy LogsHTTP Metadata Events

Required Tables

NETWORK_HTTP

False Positives & Tuning

  • Authorized red team assessment traffic
  • Static analysis tools crawling wiki source for documentation
  • False matches from unrelated query parameters containing substring 'eval'

Other platforms for CVE-2026-52778


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Simulate malicious formula eval() payload submission

    Expected signal: Web server access log entry showing POST to /?BazaR/formulaire with body containing 'eval(system(' string; PHP error log may show eval() execution or error

  2. Test 2Simulate DoS payload via infinite loop formula expression

    Expected signal: Elevated CPU utilization on the web server host, PHP-FPM worker timeout/kill logs, web access log entry for the formula endpoint request

  3. Test 3Simulate webshell drop attempt post-exploitation

    Expected signal: File creation event under the YesWiki webroot captured by FIM/EDR, web access log entry for the formula endpoint, PHP-FPM process spawning shell command

Unlock playbooks & atomic tests with Pro

Get the full detection package for CVE-2026-52778 — response playbook and atomic red team tests, plus investigation guidance and hunting queries.

df00tech Pro — £29/user/month

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections