AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-8926

HIGH · CVSS 8.1 EPSS 3.66% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-10-08 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.1. It affects Windows, GitHub. Public exploit code or proof-of-concept references have been detected in its references.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2024-8926
Severity
HIGH
CVSS
8.1
EPSS
3.66%
Windows GitHub

Original NVD Description

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages, the fixes for  CVE-2024-4577 https://github.com/advisories/GHSA-vxpp-6299-mxw3  may still be bypassed and the same command injection related to Windows "Best Fit" codepage behavior can be achieved. This may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

Related CVEs

Other vulnerabilities affecting the same vendor(s)