CVE-2026-27613
Last modified
CVE-2026-27613 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers to bypass the web server's CGI parameter security controls. EPSS estimates a 0.75% chance of exploitation in the next 30 days.
Description
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers to bypass the web server's CGI parameter security controls. Depending on the server configuration and the specific CGI executable in use, the impact is either source code disclosure or remote code execution (RCE). Anyone hosting CGI scripts (particularly interpreted languages like PHP) using vulnerable versions of TinyWeb is impacted. The problem has been patched in version 2.01. If upgrading is not immediately possible, ensure `STRICT_CGI_PARAMS` is enabled (it is defined by default in `define.inc`) and/or do not use CGI executables that natively accept dangerous command-line flags (such as `php-cgi.exe`). If hosting PHP, consider placing the server behind a Web Application Firewall (WAF) that explicitly blocks URL query string parameters that begin with a hyphen (`-`) or contain encoded double quotes (`%22`).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ritlabs | Tinyweb | < 2.01 |
References
- https://www.masiutin.net/tinyweb-cve-2026-27613.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-27613?
How severe is CVE-2026-27613?
How do I fix CVE-2026-27613?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-27608Parse Dashboard is a standalone dashboard for managing Parse…8.1
- CVE-2026-27609Parse Dashboard is a standalone dashboard for managing Parse…6.5
- CVE-2026-2761Sandbox escape in the Graphics: WebRender component. This vu…10
- CVE-2026-27610Parse Dashboard is a standalone dashboard for managing Parse…5.3
- CVE-2026-27611FileBrowser Quantum is a free, self-hosted, web-based file m…6.5
- CVE-2026-27612Repostat is a React component to fetch and display GitHub re…6.1
- CVE-2026-27614Bugsink is a self-hosted error tracking tool. In versions pr…6.1
- CVE-2026-27615ADB Explorer is a fluent UI for ADB on Windows. In versions …7.8
- CVE-2026-27616Vikunja is an open-source self-hosted task management platfo…7.3
- CVE-2026-2762Integer overflow in the JavaScript: Standard Library compone…9.8
- CVE-2026-27621TypiCMS is a multilingual content management system based on…5.4
- CVE-2026-27622OpenEXR provides the specification and reference implementat…7.8
Are you affected by CVE-2026-27613?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
