CRITICAL
9.8 CVE-2026-52608 Published 18 Aug 2026
Reportico Web Incorrect Access Control Leads to RCE
Worried this affects one of your servers?
An incorrect access control vulnerability has been found in reportico-web versions up to and including 8.1.0.
An unauthenticated attacker can inject arbitrary PHP code into the PreExecuteCode attribute of any report, regardless of the safe_mode setting.
- Affected product: reportico-web <= 8.1.0
- Attack requirement: unauthenticated access
- Impact: remote code execution
Reference: CVE-2026-52608 on NVD
← Back to Security News