/Vulnerability Library

OpenCATS - Command Injection

CVE-2026-27760
Verified

Description

OpenCATS prior to commit 3002a29 contains a command injection caused by injection of PHP statements into the installer AJAX endpoint's databaseConnectivity action parameter, letting unauthenticated attackers execute arbitrary code, exploit requires incomplete installation wizard.

Severity

High

CVSS Score

8.1

Exploit Probability

3%

Affected Product

opencats

Published Date

June 17, 2026

Template Author

theamanrawat

CVE-2026-27760.yaml
8.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-27760
CWE ID:
cwe-94

References

https://chocapikk.com/posts/2026/opencats-installer-rce/https://github.com/opencats/OpenCATS/commit/3002a29f4c3cada1aa2c4f3d4ae4e189906606b6https://github.com/opencats/OpenCATShttps://nvd.nist.gov/vuln/detail/CVE-2026-27760

Remediation Steps

Update to the version after commit 3002a29 or latest available version.