Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-12116: Xerte Online Tools allows attackers to run malicious code

CVE-2026-12116 CVE-2026-12116
Summary

The Xerte Online Tools have a security flaw that allows attackers to run their own code on the server. This can happen if the server settings are misconfigured, allowing an attacker to change the path to a PHP interpreter. To stay secure, update the Xerte Online Tools to the latest version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
xerte xerte online tools < v3.15.5
< 3.14.6
Original title
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PH...
Original description
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.
Vulnerability type
CWE-94 Code Injection
Published: 9 Jul 2026 · Updated: 20 Jul 2026 · First seen: 9 Jul 2026