
🚨 HIGH - Xerte Online Tools tools server config RCE via antivirus binary path (CVE-2026-12116) Xerte Online Tools is vulnerable to remote code execution due to an unsafe “antivirus binary path” setting in the tools server configuration component. The root cause is improper input validation and insecure configuration handling that allows an executable path to be repointed to an interpreter. An attacker who can modify this configuration can set the antivirus path to a PHP interpreter and then upload PHP content that gets executed through the scanning workflow. Successful exploitation results in arbitrary code execution on the Xerte server, enabling full system compromise, data theft, and lateral movement. 👉 Affected: Xerte Online Tools (versions not specified; assume all deployments using tools server config) | Upgrade to No fix yet — treat as suspicious
Post summary
The post announces that Xerte Online Tools suffers from an RCE vulnerability caused by an unsafe antivirus binary path setting, with no patch available yet.


