PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-52610 reportico-web CVE debrief

The CVE-2026-52610 vulnerability is an arbitrary file write/directory traversal issue in reportico-web version 8.1.0 or earlier. This vulnerability allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user. The exploit involves specifying a filename in the 'saveTemplate' parameter in conjunction with 'execute_mode=PREPARE' parameter in the 'run.php' endpoint. Organizations should be aware of the potential impact of this vulnerability on their systems and take steps to mitigate it. The CVE record was published on 2026-08-18T18:18:20.263Z and has not been modified since then. The vulnerability has a CVSS score of 9.1 and is considered CRITICAL. The affected product is reportico-web, and the vulnerability is triggered by a specific combination of parameters in the 'run.php' endpoint.

Vendor
reportico-web
Product
reportico
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-31
Advisory published
2026-08-18
Advisory updated
2026-08-31

Who should care

Organizations using reportico-web version 8.1.0 or earlier should be aware of this vulnerability and take steps to mitigate it. This includes reviewing their current deployments, assessing potential exposure, and planning for vendor-supported updates or mitigations. Additionally, organizations should review compensating controls for exposed systems while remediation is scheduled and verified. The vulnerability can be exploited by remote attackers, and the impact could be significant if not properly addressed. Therefore, it is crucial for organizations to prioritize patching and monitor for suspicious file modifications. The CVE-2026-52610 vulnerability affects reportico-web and has a CVSS score of 9.1, indicating a high severity level. Organizations should also track exceptions, retest remediated assets, and close the item only after evidence is documented. This will help ensure that the vulnerability is properly addressed and that the risk is mitigated. The affected product, reportico-web, is used in various environments, and the vulnerability can have a significant impact on the security of these environments if not properly addressed. Therefore, it is essential for organizations to take immediate action to mitigate the vulnerability and prevent potential attacks. The vulnerability can be triggered by specifying a filename in the 'saveTemplate' parameter in conjunction with 'execute_mode=PREPARE' parameter in the 'run.php' endpoint, making it essential for organizations to review their current deployments and assess potential exposure. The CVE record provides additional information about the vulnerability, including its CVSS score and the affected product. Organizations should review this information and use it to inform their mitigation efforts. By taking immediate action to mitigate the vulnerability, organizations can help prevent potential attacks and protect their systems from exploitation. The vulnerability is considered CRITICAL, and its impact can be significant if not properly addressed. Therefore, it is crucial for organizations to prioritize patching and take steps to mitigate the vulnerability. The affected product, reportico-web, is used in a web

Technical summary

The CVE-2026-52610 vulnerability is an arbitrary file write/directory traversal issue in reportico-web version 8.1.0 or earlier. The vulnerability can be exploited by remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user. The exploit involves specifying a filename in the 'saveTemplate' parameter in conjunction with 'execute_mode=PREPARE' parameter in the 'run.php' endpoint.

Defensive priority

Organizations using reportico-web version 8.1.0 or earlier should prioritize patching to prevent potential arbitrary file writes and directory traversal attacks.

Recommended defensive actions

  • Patch reportico-web to version greater than 8.1.0
  • Restrict access to the 'run.php' endpoint
  • Monitor for suspicious file modifications
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE description indicates an arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0. The vulnerability allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user. The vulnerability is triggered by specifying a filename in the 'saveTemplate' parameter in conjunction with 'execute_mode=PREPARE' parameter in the 'run.php' endpoint.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-52610 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-52610

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-52610 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52610

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.