CVE-2026-26699Disclosure(jon-remus-sevellejo / personnel_property_equipment_system)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin_change_picture.php.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • personnel_property_equipment_system

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
personnel_property_equipment_system

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 103-0503-0603-07
Signal classification1 categories
Disclosure
3100.0%
Referenced assets1 URL
By indicator
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26699 (CVSS:7.2, HIGH) is Modified. sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin..https://nvd.nist.gov/vuln/detail/CVE-2026-26699 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-26699, noting its CVSS score and that it permits arbitrary code execution in a specific system, but offers no further technical details or mitigation steps.

    0000065
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26699 (CVSS:7.2, HIGH) is Modified. sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin..https://nvd.nist.gov/vuln/detail/CVE-2026-26699 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE-2026-26699, noting its CVSS score and that it allows arbitrary code execution in the sourcecodester Personnel Property Equipment System v1.0, but provides no PoC, exploit, or remediation details.

    0000041
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26699 (CVSS:7.2, HIGH) is Modified. sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin..https://nvd.nist.gov/vuln/detail/CVE-2026-26699 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE-2026-26699, indicating an arbitrary‑code‑execution vulnerability in sourcecodester Personnel Property Equipment System v1.0 with a CVSS score of 7.2, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000042
    173 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjon-remus-sevellejopersonnel_property_equipment_system1.0--

Explore more