PT-2026-77234 · Undefined · Undefined

CVE-2026-52610

·

Published

2026-08-18

·

Updated

2026-08-31

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions reportico-web versions prior to 8.1.1
Description An arbitrary file write and directory traversal issue exists where remote attackers can create or overwrite files on the filesystem based on the web user permissions. This occurs at the 'run.php' endpoint when the saveTemplate parameter is used in conjunction with the execute mode=PREPARE parameter.
Recommendations Update reportico-web to a version newer than 8.1.0. Avoid using the saveTemplate parameter at the 'run.php' endpoint until the software is updated.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52610

Affected Products

Undefined