PT-2026-77232 · Unknown · Reportico Web

CVE-2026-52608

·

Published

2026-08-18

·

Updated

2026-08-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions reportico-web versions prior to 8.1.1
Description An incorrect access control issue allows an unauthenticated attacker to inject arbitrary PHP code into the PreExecuteCode attribute of any report. This occurs regardless of the safe mode setting and can lead to remote code execution, which is the ability of an attacker to execute malicious commands on the host machine.
Recommendations Update reportico-web to a version newer than 8.1.0.

Exploit

Fix

RCE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52608

Affected Products

Reportico Web