PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-52608 reportico-web CVE debrief

An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution. This critical vulnerability, with a CVSS score of 9.8, affects reportico-web installations and requires immediate attention from security teams and administrators. They should prioritize patching and monitoring due to the high severity and potential impact of remote code execution. The vulnerability enables attackers to inject arbitrary PHP code, leading to potential system compromise. Security teams should verify reportico-web deployments, review official advisories, and monitor for suspicious activity to ensure proper mitigation and prevent exploitation.

Vendor
reportico-web
Product
reportico-web
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-31
Advisory published
2026-08-18
Advisory updated
2026-08-31

Who should care

Security teams and administrators responsible for reportico-web installations should prioritize patching and monitoring due to the high severity and potential impact of remote code execution. They should review official advisories, verify deployments, and ensure proper mitigation to prevent exploitation. Additionally, operators and platform administrators may need to assess the vulnerability's impact on their environments and take appropriate actions.

Technical summary

The vulnerability allows an unauthenticated attacker to inject arbitrary PHP code into the PreExecuteCode attribute of any report in reportico-web version 8.1.0 and earlier, regardless of the safe_mode setting. This leads to remote code execution with a CVSS score of 9.8, classified as CRITICAL. The vulnerability affects reportico-web installations, and security teams should prioritize patching and monitoring due to the high severity and potential impact of remote code execution.

Defensive priority

High priority due to critical CVSS score of 9.8 and potential for remote code execution.

Recommended defensive actions

  • Verify reportico-web version and apply patch if available
  • Restrict access to reportico-web
  • Monitor reportico-web logs for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

Evidence from official CVE and NVD sources indicates a critical vulnerability in reportico-web version 8.1.0 and earlier. However, detailed information about affected configurations and vendor remediation is limited. Security teams should verify reportico-web deployments, review official advisories, and monitor for suspicious activity. The CVE record was published on 2026-08-18T18:18:20.020Z and has not been modified since then. Additional verification is required to assess the full impact and ensure proper mitigation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-52608 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-52608

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-52608 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52608

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.