A vulnerability was found in DedeCMS up to 5.7.118 . It has been declared as critical . The affected element is the function array_filter . Executing a manipulation can lead to privilege escalation. This vulnerability is tracked as CVE-2026-30694 . The attack can be launched remotely. No exploit exists.