PT-2026-38297 · Scramble · Scramble
CVE-2026-44262
·
Published
2026-04-28
·
Updated
2026-08-03
CVSS v2.0
9.7
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
Scramble versions 0.13.2 through 0.13.21
Description
An issue exists in the way the software manages code generation. When documentation endpoints are publicly accessible and validation rules reference user-controlled input, data supplied in the request may be evaluated during the documentation generation process. This can allow a remote attacker to execute arbitrary PHP code within the application context. The affected endpoints include
/docs/api and /docs/api.json.Recommendations
Update to version 0.13.22.
Restrict access to the
/docs/api and /docs/api.json endpoints.
Avoid using user-controlled variables inside validation rule expressions.
Disable documentation endpoints in production environments if they are not required.Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scramble