CVE-2026-63722
Last modified
CVE-2026-63722 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP POST request to the terminal endpoint with a password parameter to bypass authentication, a non-empty csrf parameter to skip CSRF validation, and an arbitrary command string passed directly to proc_open() to achieve remote code execution as the web-server user.. EPSS estimates a 1.52% chance of exploitation in the next 30 days.
Description
ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP POST request to the terminal endpoint with a password parameter to bypass authentication, a non-empty csrf parameter to skip CSRF validation, and an arbitrary command string passed directly to proc_open() to achieve remote code execution as the web-server user.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ICEcoder | ICEcoder | <= 8.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-63722?
How severe is CVE-2026-63722?
How do I fix CVE-2026-63722?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63700Dell Wyse Management Suite (WMS), versions prior to 2605.0.2…7.8
- CVE-2026-63701Dell Wyse Management Suite (WMS), versions prior to 2605.0.2…7.8
- CVE-2026-63702Dell Wyse Management Suite (WMS), versions prior to 2605.0.2…5.5
- CVE-2026-6371Improper neutralization of input during web page generation …4.8
- CVE-2026-6372Missing Authorization vulnerability in Plisio Accept Cryptoc…7.5
- CVE-2026-63720datamodel-code-generator prior to version 0.70.0 contains a …7.5
- CVE-2026-63723Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-63725sysPass's FileBackupService::doBackupFiles() in lib/SP/Servi…7.2
- CVE-2026-63726Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-63727Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 …8.8
- CVE-2026-63728Gitleaks prior to 8.30.1 contains a template injection vulne…8.1
- CVE-2026-63729The SyncTeX parser (synctex_parser.c) shipped with TeX Live …6.8
Are you affected by CVE-2026-63722?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
