PT-2026-22037 · Php+1 · Php+1

Maximmasiutin

·

Published

2026-02-25

·

Updated

2026-03-04

·

CVE-2026-27613

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions TinyWeb versions prior to 2.01
Description TinyWeb, a web server for Win32, contains a flaw where unauthenticated remote attackers can circumvent the CGI parameter security controls. This can lead to source code disclosure or remote code execution (RCE), depending on the server’s configuration and the CGI executable being used. Systems hosting CGI scripts, such as PHP, are potentially affected. The issue is addressed in version 2.01.
Recommendations Update to version 2.01. If an immediate upgrade is not possible, ensure STRICT CGI PARAMS is enabled. If hosting PHP, consider placing the server behind a Web Application Firewall (WAF) that blocks URL query string parameters beginning with a hyphen (-) or containing encoded double quotes (%22).

Exploit

Fix

RCE

Argument Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-27613
GHSA-RFX5-FH9M-9JJ9

Affected Products

Php
Tinyweb