
New blog post - CVE-2026-27760 Unauthenticated RCE in OpenCATS via installer config injection. Unsanitized input written directly into config.php, CVSS 9.2. https://chocapikk.com/posts/2026/opencats-installer-rce/
Post summary
The post discloses a high‑severity, unauthenticated RCE in OpenCATS (CVE‑2026‑27760), with technical details and a link to a blog that likely contains a PoC, but no patch, exploit code, or evidence of active exploitation is provided.



