CVE-2026-27892Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, without stripping EXIF/XMP/IPTC metadata. Any authenticated user who downloaded an image could extract the uploader's embedded metadata, which included GPS coordinates, device information, timestamps, embedded comments/notes, thumbnail previews, and other personally identifiable information (PII) preserved in the image metadata. Of all FacturaScripts' image upload features, only the Library module combined unrestricted uploads, persistent storage, authenticated download access, and a total lack of server-side metadata sanitization. This vulnerability carries significant real-world impact: an employee uploading a photo taken at their home inadvertently discloses their precise home address to every user with Library download access. This issue has been fixed in version 2026.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-212

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-19)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-18: 1Mentions · 2026-05-19: 2Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 105-1805-19
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-181
Disclosure1
2026-05-192
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-27892 FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, wit… https://www.cve.org/CVERecord?id=CVE-2026-27892 ----- Traducción: CVE-2026-27892 Fac… http://infoflow.cloud`

    Post summary

    The post references CVE‑2026‑27892 and links to its CVE record, but offers no evidence of a PoC, exploit, active exploitation, patch, or detailed technical information.

    0000053
    78 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27892 FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, wit… https://www.cve.org/CVERecord?id=CVE-2026-27892

    Post summary

    The post provides a brief disclosure of CVE-2026-27892, outlining how the library module handles uploaded images but offers no PoC, exploit code, or patch details.

    00000168
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27892 Metadata Disclosure in FacturaScripts Library Module Prior to Ver... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27892 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post announces CVE‑2026‑27892 as a metadata disclosure vulnerability in the FacturaScripts library module, providing a link to detailed information but no PoC, exploit, or mitigation details.

    0000057
    4.0K followersView on X

Explore more