Description
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.
Published: 2026-07-09
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can modify the antivirus binary path configuration in Xerte Online Tools so that it points to a PHP interpreter instead of a legitimate antivirus program. When the path is altered, files uploaded to the server are treated as PHP code and executed by the web server process, providing the attacker with the ability to run arbitrary commands with the privileges of the web server and effectively compromising the entire system.

Affected Systems

The vulnerability affects Xerte Online Tools from the Xerte project. No specific product versions are listed in the CVE data; however, the references indicate that versions 3.14 and 3.15 received a security update, suggesting these releases may contain the fix.

Risk and Exploitability

The CVSS score of 9.8 categorizes the flaw as Critical, while the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote: an adversary who can modify configuration settings or upload files can trigger the execution of injected PHP code.

Generated by OpenCVE AI on July 29, 2026 at 12:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Xerte Online Tools security update (e.g., versions 3.14 or 3.15) that addresses the antivirus path validation issue.
  • Verify that the antivirus binary setting points to a legitimate antivirus executable and is not configured to a PHP interpreter.
  • Restrict PHP execution in upload directories by configuring the web server to block PHP parsing for those paths and enforce strict file type validation for uploads.

Generated by OpenCVE AI on July 29, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Sat, 25 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Wed, 22 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 14 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-73

Mon, 13 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-73

Sun, 12 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-95

Sat, 11 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-95

Fri, 10 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78
CWE-94

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Xerte
Xerte xerte Online Tools
Vendors & Products Xerte
Xerte xerte Online Tools

Thu, 09 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78
CWE-94

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.
Title CVE-2026-12116
References

Subscriptions

Xerte Xerte Online Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-07-09T15:15:34.035Z

Reserved: 2026-06-12T14:47:35.871Z

Link: CVE-2026-12116

cve-icon Vulnrichment

Updated: 2026-07-09T15:15:24.262Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:30:03Z

Weaknesses

No weakness.