PT-2026-55934 · Unknown · Modsecurity

CVE-2026-52761

·

Published

2026-07-06

·

Updated

2026-07-15

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ModSecurity versions 3.0.0 through 3.0.15
Description The t:utf8toUnicode transformation in src/actions/transformations/utf8 to unicode.cc produces incorrect output on i386 architecture. This occurs because the snprintf() function uses sizeof on a char pointer instead of the actual length of the unicode buffer, which allows security rules utilizing this transformation to be bypassed on i386 systems.
Recommendations Update to version 3.0.16.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MODSECURITY-2026-52761
BIT-MODSECURITY2-2026-52761
CVE-2026-52761
GHSA-QJGM-7GP4-F8QQ

Affected Products

Modsecurity