SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-52607

MEDIUM · CVSS 6.5 EPSS 0.56% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A directory traversal vulnerability in reportico-web versions up to 8.1.0 allows remote attackers to access or execute arbitrary PHP files on the web server by manipulating the target_format parameter alongside the execute_mode=EXECUTE parameter in the run.php endpoint. This could lead to unauthorized access to sensitive files or execution of malicious scripts, posing a significant risk to the integrity and confidentiality of the server. Organizations using affected versions should prioritize patching this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-52607
Severity
MEDIUM
CVSS
6.5
EPSS
0.56%

Original NVD Description

A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web server by specifying the filename in the target_format parameter in conjunction with the execute_mode=EXECUTE parameter of the run.php endpoint.