CVE-2026-3057Disclosure(a54552239 / pearprojectapi)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch a54552239 pearprojectapi systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/common/Model/Task.php of the component Backend Interface. The manipulation of the argument projectCode results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pearprojectapi

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
pearprojectapi

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-24: 1Mentions · 2026-02-25: 1Mentions · 2026-02-26: 1PoC Mentioned / Linked · 2026-02-25: 1PoC Mentioned / Linked · 2026-02-26: 1Active Exploitation · 2026-02-26: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 102-2402-2502-26
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-241
Disclosure1
2026-02-251
Disclosure1
2026-02-261
General1
Full discourse3 posts
  • NerdieNews@NewsNerdie
    General

    Today's Top Cybersecurity News – February 26, 2026 1. CVE-2026-3057: SQL Injection in pearProjectApi Backend Task.php dateTotalForProject A remote SQL injection vulnerability exists in the dateTotalForProject function of pearProjectApi up to version 2.8.10, allowing attackers to manipulate the projectCode argument. The exploit is publicly available, increasing the risk of unauthorized data access or modification. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-3057 2. Critical Authentication Bypass and Privilege Escalation Vulnerabilities in Cisco Catalyst SD-WAN Multiple critical vulnerabilities in Cisco Catalyst SD-WAN products allow unauthenticated remote attackers to bypass authentication, escalate privileges to admin or root, and take full control of affected devices. Notably, CVE-2026-20127 has been actively exploited in zero-day attacks since 2023, enabling attackers to compromise controllers and insert rogue peers into networks. Users are urged to identify vulnerable devices, collect forensic data, update to patched versions, and conduct threat hunting. Sources: Bleepingcomputer, Cvefeed, Cyberscoop, Feedburner, Gbhackers, Kyberturvallisuuskeskus, Rapid7, Talosintelligence, Therecord https://www.kyberturvallisuuskeskus.fi/fi/kriittisia-haavoittuvuuksia-cisco-catalyst-sd-wan-tuotteissa 3. Multiple Critical and High Vulnerabilities Found in Binardat 10G08-0800GSM Network Switch A series of critical and high-severity vulnerabilities have been identified in Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209. These include hard-coded credentials, predictable session IDs, plaintext password exposure, weak encryption, and command injection, exposing devices to unauthorized access, credential compromise, and remote code execution. Medium-severity issues such as missing login rate limiting, CSRF, and XSS further increase the attack surface. Sources: Bleepingcomputer, Cvefeed, Securityweek https://cvefeed.io/vuln/detail/CVE-2026-27521 4. Multiple Vulnerabilities Disclosed Including Critical Path Traversal in Local Path Provisioner Several security vulnerabilities were disclosed affecting various platforms including Octopus Deploy, Red Hat Developer Hub, openSUSE, Udisks, Rancher CLI, and Local Path Provisioner. Notably, a critical path traversal vulnerability in Local Path Provisioner allows attackers to overwrite sensitive files, while other issues range from denial of service to unauthorized access of encryption metadata. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-0704 5. Multiple Critical Vulnerabilities in FreeRDP Affecting Versions Prior to 3.23.0 FreeRDP versions before 3.23.0 contain multiple severe vulnerabilities including heap-use-after-free, out-of-bounds writes, integer overflow, and denial-of-service flaws. These issues can lead to client or server crashes, memory corruption, and potential remote code execution, especially when interacting with malicious RDP servers or crafted data. A patch addressing all these vulnerabilities is available in version 3.23.0. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-27951 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The post highlights multiple critical CVEs, noting active exploitation of a Cisco SD‑WAN vulnerability and publicly available exploits for a SQL injection. Patches are available for several, but some remain unpatched.

    0000037
    54 followersView on X
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 25, 2026 1. CVE-2026-3057: SQL Injection in pearProjectApi Backend Task.php dateTotalForProject A remote SQL injection vulnerability exists in the dateTotalForProject function of pearProjectApi up to version 2.8.10, allowing attackers to manipulate the projectCode argument. The exploit is publicly available, increasing the risk of unauthorized data access or modification. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-3057 2. Critical Remote Code Execution Vulnerabilities Found in SolarWinds Serv-U Multiple critical remote code execution vulnerabilities, including IDOR, type confusion, and broken access control, have been discovered in SolarWinds Serv-U. These flaws allow attackers with administrative privileges to execute arbitrary code or create privileged accounts, posing significant risks especially in environments where services run with elevated rights. Sources: Crowdstrike, Cvefeed, Darkreading, Gbhackers, Malwarebytes, Microsoft, Securityaffairs, Securityweek https://cvefeed.io/vuln/detail/CVE-2025-40541 3. Multiple Critical Vulnerabilities Discovered in Traccar GPS Tracking System Traccar versions up to 6.11.1 are affected by several critical security flaws including stored XSS via malicious SVG uploads, path traversal allowing arbitrary file writes, Cross-Site WebSocket Hijacking due to missing origin validation, and OAuth 2.0 authorization code theft through open redirect vulnerabilities. These issues allow authenticated attackers to execute arbitrary scripts, manipulate files on the server, hijack WebSocket sessions, and steal sensitive authorization tokens, posing significant risks to user data and system integrity. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-25648 4. Critical Vulnerabilities in Parse Dashboard AI Agent Endpoint Allow Unauthorized Access and CSRF Attacks Multiple vulnerabilities in Parse Dashboard versions 7.3.0-alpha.42 through 9.0.0-alpha.7 affect the AI Agent API endpoint, including missing CSRF protection, lack of authorization enforcement, and incomplete authentication. These flaws enable attackers to perform unauthorized actions, escalate privileges, and potentially access any connected Parse Server database using the master key. The issues have been addressed starting from version 9.0.0-alpha.8. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-27609 5. Ransomware Attacks on Romania and Mississippi Highlight Growing Threat to Critical Infrastructure Ransomware campaigns targeting Romania's critical infrastructure are reportedly linked to Russian geopolitical strategies, indicating a hybrid warfare approach. Separately, a ransomware attack on the University of Mississippi Medical Center forced closure of all clinics and cancellation of procedures, demonstrating the severe operational impact on healthcare services. Sources: Feedburner, Gbhackers, Infosecurity-Magazine, Sans, Securityweek, Therecord https://therecord.media/ransomware-gangs-advancing-moscow-geopolitical-interests-warns-romania Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The article reports several newly disclosed vulnerabilities with technical details and patch status, noting that one exploit is publicly available but no active exploitation or false positive claims are mentioned.

    0000037
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3057 A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/common/Model/Task.php… https://www.cve.org/CVERecord?id=CVE-2026-3057

    Post summary

    A vulnerability (CVE-2026-3057) was identified in pearProjectApi up to version 2.8.10, affecting the dateTotalForProject function in Task.php, with no PoC, exploit, or patch details provided.

    0000096
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appa54552239pearprojectapi---

Explore more