An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 18 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated PHP Code Injection via Reportico-web PreExecuteCode Attribute | |
| Weaknesses | CWE-284 CWE-94 |
Tue, 18 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-18T17:12:45.377Z
Reserved: 2026-06-08T00:00:00.000Z
Link: CVE-2026-52608
No data.
Status : Received
Published: 2026-08-18T18:18:20.020
Modified: 2026-08-18T18:18:20.020
Link: CVE-2026-52608
No data.
OpenCVE Enrichment
Updated: 2026-08-18T19:30:04Z
Weaknesses
No weakness.