CRITICAL 9.8 CVE-2026-52608 Published 18 Aug 2026

Reportico Web Incorrect Access Control Leads to RCE

Worried this affects one of your servers?

An incorrect access control vulnerability has been found in reportico-web versions up to and including 8.1.0.

An unauthenticated attacker can inject arbitrary PHP code into the PreExecuteCode attribute of any report, regardless of the safe_mode setting.

  • Affected product: reportico-web <= 8.1.0
  • Attack requirement: unauthenticated access
  • Impact: remote code execution

Reference: CVE-2026-52608 on NVD

← Back to Security News