CVE-2026-27760
Last modified
CVE-2026-27760 is a critical-severity vulnerability rated 9.2/10 on the CVSS scale. OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string context in config.php using a single quote and statement separator to inject malicious PHP code that persists and executes on every subsequent page load when the installation wizard remains incomplete.. EPSS estimates a 22.19% chance of exploitation in the next 30 days.
Description
OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string context in config.php using a single quote and statement separator to inject malicious PHP code that persists and executes on every subsequent page load when the installation wizard remains incomplete.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-27760?
How severe is CVE-2026-27760?
How do I fix CVE-2026-27760?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-27755SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 c…9.8
- CVE-2026-27756SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 c…6.1
- CVE-2026-27757SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 c…7.2
- CVE-2026-27758SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 c…6.5
- CVE-2026-27759Featured Image from Content (featured-image-from-content) Wo…5.3
- CVE-2026-2776Sandbox escape due to incorrect boundary conditions in the T…10
- CVE-2026-27761Gitea versions up to and including 1.26.2 allow repository R…4.3
- CVE-2026-27764The WebSocket backend uses charging station identifiers to u…8.6
- CVE-2026-27765Improper input validation for some vLLM Hardware Plugin for …6.8
- CVE-2026-27766in OpenHarmony v6.0 and prior versions allow a local attacke…5.5
- CVE-2026-27767WebSocket endpoints lack proper authentication mechanisms, e…9.8
- CVE-2026-27768SQL Injection affecting the Access Manager role.6.6
Are you affected by CVE-2026-27760?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
