CVE-2026-27613Disclosure(ritlabs / tinyweb)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch ritlabs tinyweb systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers to bypass the web server's CGI parameter security controls. Depending on the server configuration and the specific CGI executable in use, the impact is either source code disclosure or remote code execution (RCE). Anyone hosting CGI scripts (particularly interpreted languages like PHP) using vulnerable versions of TinyWeb is impacted. The problem has been patched in version 2.01. If upgrading is not immediately possible, ensure `STRICT_CGI_PARAMS` is enabled (it is defined by default in `define.inc`) and/or do not use CGI executables that natively accept dangerous command-line flags (such as `php-cgi.exe`). If hosting PHP, consider placing the server behind a Web Application Firewall (WAF) that explicitly blocks URL query string parameters that begin with a hyphen (`-`) or contain encoded double quotes (`%22`).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-88

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tinyweb

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-26)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
tinyweb

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-25: 1Mentions · 2026-02-26: 3Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 302-2502-26
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-251
Disclosure1
2026-02-263
Disclosure2Patch1
Full discourse4 posts
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-27613 in TinyWeb (<2.01) allows unauthenticated OS command injection — RCE risk! Patch to 2.01 or enable STRICT_CGI_PARAMS. Hosting CGI scripts like PHP? Act now! https://radar.offseq.com/threat/cve-2026-27613-cwe-78-improper-neutralization-of-s-552b887a #... https://t.co/jTT4r2MTXS

    Post summary

    CVE-2026-27613 is a critical OS command injection vulnerability in TinyWeb versions below 2.01, with a patch available (upgrade to 2.01 or enable STRICT_CGI_PARAMS).

    0001065
    270 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27613 TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers to bypass the web… https://www.cve.org/CVERecord?id=CVE-2026-27613 ----- Traducción: CVE-2026-27613 Tin… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-27613, a remote unauthenticated bypass vulnerability in TinyWeb, with a link to the CVE record.

    0000031
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27613 TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers to bypass the web… https://www.cve.org/CVERecord?id=CVE-2026-27613

    Post summary

    CVE-2026-27613 is a vulnerability in TinyWeb that permits unauthenticated remote attackers to bypass web authentication in versions before 2.01.

    00000162
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27613 TinyWeb CGI Parameter Bypass Vulnerability Enables Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27613

    Post summary

    A new CVE (CVE-2026-27613) for TinyWeb CGI parameter bypass enabling remote code execution is disclosed, with no PoC, exploit, patch, or active exploitation details provided.

    0000046
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appritlabstinyweb---

Explore more