PT-2026-35727 · Opencats · Opencats
Valentin Lobstein
+1
·
Published
2026-04-28
·
Updated
2026-06-17
·
CVE-2026-27760
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenCATS versions prior to commit 3002a29
Description
An unauthenticated PHP code injection issue exists in the installer AJAX endpoint. This allows attackers to execute arbitrary code by injecting PHP statements into the
databaseConnectivity action parameter. By using a single quote and statement separator, an attacker can break out of the define() string context in the config.php file. The injected malicious code persists and executes on every subsequent page load as long as the installation wizard remains incomplete.Recommendations
Update to commit 3002a29 or a newer version.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opencats