CRITICAL
9.1 CVE-2026-52610 Published 18 Aug 2026
Reportico Web Directory Traversal Arbitrary File Write Vulnerability
Worried this affects one of your servers?
A vulnerability in reportico-web versions up to and including 8.1.0 allows arbitrary file write/directory traversal.
Remote attackers can create or overwrite files anywhere on the filesystem, subject to the permissions of the web user, by specifying a filename in the saveTemplate parameter together with execute_mode=PREPARE in the run.php endpoint.
- Affected versions: reportico-web <= 8.1.0
- Impact: arbitrary file creation or overwrite on the filesystem
- Condition: attacker-controlled filename via saveTemplate and execute_mode=PREPARE
Reference: CVE-2026-52610 on NVD
← Back to Security News