CVE-2026-31843Disclosure

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any without authentication middleware, enabling remote access without credentials.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-04-17); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-16: 1Mentions · 2026-04-17: 4Mentions · 2026-04-18: 1PoC Mentioned / Linked · 2026-04-16: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 3Technical Details · 2026-04-18: 104-1604-1704-18
Signal classification2 categories
Disclosure
583.3%
PoC
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-161
PoC1
2026-04-174
Disclosure4
2026-04-181
Disclosure1
Full discourse6 posts
  • CTIWatch@ctiwatchcloud
    Disclosure

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-6443 | CVSS 9.8 🔴 CVE-2026-37345 | CVSS 9.8 🔴 CVE-2026-31843 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post announces three high‑score CVEs, offering a link for further information but no additional technical or exploitation details.

    0001054
    5.6K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical vulnerability in `goodoneuz/pay-uz` (CVE-2026-31843) allows overwriting PHP payment hook files. This can lead to RCE. Investigate and secure installations. #PHP #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-31843-goodoneuz-pay-uz-php-file-overwrite

    Post summary

    The post announces CVE-2026-31843, describing how overwriting PHP payment hook files can lead to remote code execution and urges administrators to investigate and secure their installations.

    0000055
    12 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-31843 affects goodoneuz/pay-uz (&lt;=2.2.24) Attackers can overwrite PHP payment files with user-controlled content. Assessed as Tier 2: high impact Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-04-16/TIER_2_CVE-2026-31843.md #cybersecurity #appsec #laravel #rce #cve

    Post summary

    Announces CVE-2026-31843 as a high‑impact flaw that allows attackers to overwrite PHP payment files in goodoneuz/pay‑uz (<=2.2.24), with a link to a detailed GitHub report.

    0000056
    45 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31843 The goodoneuz/pay-uz Laravel package (&lt;= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers … https://www.cve.org/CVERecord?id=CVE-2026-31843 ----- Traducción: CVE-2026-31843 El … http://infoflow.cloud`

    Post summary

    The tweet discloses a critical vulnerability in the goodoneuz/pay-uz Laravel package’s payment API endpoint that permits unauthenticated attackers to intervene.

    0000039
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31843 The goodoneuz/pay-uz Laravel package (&lt;= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers … https://www.cve.org/CVERecord?id=CVE-2026-31843

    Post summary

    A critical vulnerability (CVE-2026-31843) has been identified in the goodoneuz/pay‑uz Laravel package, affecting the /payment/api/editable/update endpoint and permitting unauthenticated attacks.

    00000229
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-31843: goodoneuz (CVSS: 10.0)... Route::any() + file_put_contents() = instant RCE factory - Laravel devs just handed attackers executable PHP shells on ... https://zerodaysignal.com/vulnerability/CVE-2026-31843 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-31843 with a CVSS score of 10.0, describes an RCE via Laravel's Route::any and file_put_contents, and provides a link to a PoC.

    0000045
    218 followersView on X

Explore more