Description
A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control.
Published: 2026-07-09
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Xerte Online Tools setup component allows an unauthenticated attacker to trigger a full re‑installation through the /setup/ directory. During that process the attacker can supply a database connection string, causing the application to bind to an arbitrary database under the attacker’s control. This bypasses the normal authentication flow and effectively permits the attacker to execute arbitrary commands on the host server.

Affected Systems

The vulnerability affects Xerte Online Tools provided by Xerte. The advisory does not specify a limited set of affected releases, although the vendor’s news page indicates that versions 3.14 and 3.15 contain a corrective change. Precise version compatibility remains administrator‑specific; verify the deployed version and ensure that the /setup/ directory is either removed or otherwise inaccessible after initial configuration.

Risk and Exploitability

The flaw carries a CVSS score of 9.1, indicating critical severity. The EPSS score of less than 1 % indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV. Attackers can exploit the flaw by sending unauthenticated HTTP requests to the /setup/ endpoint, which may be possible over the internet if the directory is publicly reachable. The lack of authentication or rate limiting on this endpoint eliminates most practical barriers to exploitation.

Generated by OpenCVE AI on July 26, 2026 at 15:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Xerte Online Tools 3.14 or later, which removes the ability to trigger a re‑installation from an external location.
  • Configure the web server to block external access to the /setup/ directory, or delete the directory once initial installation is complete.
  • Ensure that installation credentials do not allow connecting to arbitrary or untrusted databases, and enforce network or database‑level restrictions as appropriate.

Generated by OpenCVE AI on July 26, 2026 at 15:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-287

Wed, 22 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-94

Tue, 21 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-94

Fri, 17 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-78

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-78

Mon, 13 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Sun, 12 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Sat, 11 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-77

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Xerte
Xerte xerte Online Tools
Vendors & Products Xerte
Xerte xerte Online Tools

Thu, 09 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-77

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control.
Title CVE-2026-14261
References

Subscriptions

Xerte Xerte Online Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-07-09T15:21:38.397Z

Reserved: 2026-06-30T16:15:16.781Z

Link: CVE-2026-14261

cve-icon Vulnrichment

Updated: 2026-07-09T14:51:02.320Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T15:30:04Z

Weaknesses