CVE-2026-52608

CVE-2026-52608CVE-2026-52608

Description

An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution.

Scoring

Last modified2026-08-18
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.