PT-2026-35727 · Opencats · Opencats

Valentin Lobstein

+1

·

Published

2026-04-28

·

Updated

2026-06-17

·

CVE-2026-27760

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenCATS versions prior to commit 3002a29
Description An unauthenticated PHP code injection issue exists in the installer AJAX endpoint. This allows attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. By using a single quote and statement separator, an attacker can break out of the define() string context in the config.php file. The injected malicious code persists and executes on every subsequent page load as long as the installation wizard remains incomplete.
Recommendations Update to commit 3002a29 or a newer version.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27760

Affected Products

Opencats