PT-2026-79580 · Fabrik · Fabrik

CVE-2026-76604

·

Published

2026-08-22

·

Updated

2026-08-24

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Fabrik versions prior to 4.7.3
Description An unauthenticated remote code execution issue exists within the PHP form element, which allows the execution of user-provided code.
Recommendations Update to version 4.7.3 or later. As a temporary workaround, restrict the use of the PHP form element to minimize the risk of exploitation.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76604

Affected Products

Fabrik