CVE-2026-8802General

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename results in path traversal. The attack may be launched remotely. The patch is identified as def0c27a0e252668df8d942fc31e16d1edfd7323. A patch should be applied to remediate this issue. The vendor was contacted early about this disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-18: 3Technical Details · 2026-05-18: 105-18
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-8802 📊 Severity: 4.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-8802 #CVE-2026-8802 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/T5ANeorCvr

    Post summary

    The tweet announces CVE-2026-8802 with a medium severity score of 4.3, notes unspecified affected products, and links to the NVD entry.

    0000051
    160 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-8802 Path Traversal in Open Source Point of Sale Up to Version 3.4.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8802

    Post summary

    The content reports a path traversal vulnerability (CVE-2026-8802) affecting versions up to 3.4.2 of an open-source point‑of‑sale system but offers no PoC, exploit, or patch details.

    0000059
    4.0K followersView on X
  • VulDB 🛡@vuldb
    General

    Our CTI team identified a lot of activities targeting opensourcepos Open Source Point of Sale (CVE-2026-8802) https://vuldb.com/vuln/364435/cti

    Post summary

    The CTI report notes increased targeting of Open Source Point of Sale (CVE‑2026‑8802) and directs readers to an external link, but provides no PoC, exploit, patch, or detailed technical data.

    0000094
    2.2K followersView on X

Explore more