PT-2026-91931 · Trexom · Trxtimeattendance

·

CVE-2026-89308

·

Published

2026-09-15

·

Updated

2026-09-15

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description An unauthenticated OS command injection flaw exists in the 'ping.php' endpoint. This allows remote attackers to execute arbitrary commands on the underlying operating system, leading to remote code execution. OS command injection is a flaw where an application passes unsafe user-supplied data to a system shell.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89308

Affected Products

Trxtimeattendance