Description
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
Published: 2026-08-06
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated attacker can exploit a flaw in Packetfence's WebGui interface configuration, enabling arbitrary command execution on the host. The vulnerability allows the attacker to run arbitrary code with the privileges of the web service, potentially compromising system integrity, confidentiality, and availability. No further details are provided, but the capability to execute code remotely places the system at high risk if accessed by malicious actors.

Affected Systems

Packetfence version 13.2.0 is vulnerable. The flaw resides in the WebGui configuration setting and is specific to that release. No other versions or products are listed.

Risk and Exploitability

The CVE has no publicly available EPSS score and is not listed in the CISA KEV catalog. However, the nature of the vulnerability—remote code execution requiring authentication—implies a high impact should credentials be compromised. The attack vector is inferred to be through the web interface after an attacker gains authenticated access; once authenticated, the attacker can manipulate the vulnerable setting to run arbitrary commands. The lack of an EPSS score means no quantitative probability is available, but the required conditions (authenticated access) suggest that an internal attacker or a compromised account poses the greatest threat.

Generated by OpenCVE AI on August 6, 2026 at 23:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Immediately upgrade Packetfence to a fixed version that removes the vulnerable WebGui setting.
  • Restrict access to the WebGui configuration interface to privileged administrators only, using strong passwords or MFA and network segmentation.
  • Temporarily disable the vulnerable WebGui setting that allows arbitrary command execution until a patch is available.
  • Audit configuration changes and monitor logs for suspicious activity to detect exploitation attempts.

Generated by OpenCVE AI on August 6, 2026 at 23:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Authenticated Remote Code Execution in Packetfence 13.2.0 WebGui
Weaknesses CWE-77

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-06T20:21:31.975Z

Reserved: 2024-06-21T00:00:00.000Z

Link: CVE-2024-39024

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T23:30:05Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')