CVE-2026-8208EPSS p32.3%
CVE-2026-8208CVE-2026-8208
Description
Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user provided .zip as PHP. Successful exploitation requires Teacher or higher privileges. Exploitation could result in compromise of the underlying web server.
Scoring
| EPSS | 0.40% probability of exploitation · percentile 32.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-24 |