PT-2026-38297 · Scramble · Scramble

CVE-2026-44262

·

Published

2026-04-28

·

Updated

2026-08-03

CVSS v2.0

9.7

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions Scramble versions 0.13.2 through 0.13.21
Description An issue exists in the way the software manages code generation. When documentation endpoints are publicly accessible and validation rules reference user-controlled input, data supplied in the request may be evaluated during the documentation generation process. This can allow a remote attacker to execute arbitrary PHP code within the application context. The affected endpoints include /docs/api and /docs/api.json.
Recommendations Update to version 0.13.22. Restrict access to the /docs/api and /docs/api.json endpoints. Avoid using user-controlled variables inside validation rule expressions. Disable documentation endpoints in production environments if they are not required.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10979
CVE-2026-44262
GHSA-4RM2-28VJ-FJ39

Affected Products

Scramble