CVE-2026-27760Disclosure

LOWCVSS 9.2 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string context in config.php using a single quote and statement separator to inject malicious PHP code that persists and executes on every subsequent page load when the installation wizard remains incomplete.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-28); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-28: 3Mentions · 2026-06-17: 1PoC Mentioned / Linked · 2026-04-28: 1Technical Details · 2026-04-28: 3Technical Details · 2026-06-17: 104-2806-17
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-283
Disclosure3
2026-06-171
Disclosure1
Full discourse4 posts
  • ʞʞıdɐɔoɥƆ@Chocapikk_
    Disclosure

    New blog post - CVE-2026-27760 Unauthenticated RCE in OpenCATS via installer config injection. Unsanitized input written directly into config.php, CVSS 9.2. https://chocapikk.com/posts/2026/opencats-installer-rce/

    Post summary

    The post discloses a high‑severity, unauthenticated RCE in OpenCATS (CVE‑2026‑27760), with technical details and a link to a blog that likely contains a PoC, but no patch, exploit code, or evidence of active exploitation is provided.

    0802471.5K
    4.0K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-27760 - high 🚨 OpenCATS - Command Injection > OpenCATS prior to commit 3002a29 contains a command injection caused by injection of ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-27760 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE‑2026‑27760 is a command‑injection flaw in OpenCATS before commit 3002a29, newly disclosed in a brief advisory.

    01012159
    959 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27760 Unauthenticated PHP Code Injection in OpenCATS Installer AJAX Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27760

    Post summary

    A new CVE, CVE‑2026‑27760, highlights an unauthenticated PHP code injection flaw in the OpenCATS installer AJAX endpoint.

    0000059
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-27760 OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows… CVSS 8.1 Full analysis → https://sec.kaitan.id/cves/CVE-2026-27760 #HP #CyberSecurity #InfoSec

    Post summary

    The text announces CVE‑2026‑27760, describing a code‑injection flaw in OpenCATS’s installer AJAX endpoint with a CVSS score of 8.1, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000040
    167 followersView on X

Explore more