CRITICAL 9.1 CVE-2026-52610 Published 18 Aug 2026

Reportico Web Directory Traversal Arbitrary File Write Vulnerability

Worried this affects one of your servers?

A vulnerability in reportico-web versions up to and including 8.1.0 allows arbitrary file write/directory traversal.

Remote attackers can create or overwrite files anywhere on the filesystem, subject to the permissions of the web user, by specifying a filename in the saveTemplate parameter together with execute_mode=PREPARE in the run.php endpoint.

  • Affected versions: reportico-web <= 8.1.0
  • Impact: arbitrary file creation or overwrite on the filesystem
  • Condition: attacker-controlled filename via saveTemplate and execute_mode=PREPARE

Reference: CVE-2026-52610 on NVD

← Back to Security News