Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-12116: Xerte Online Tools allows attackers to run malicious code
CVE-2026-12116
CVE-2026-12116
Summary
The Xerte Online Tools have a security flaw that allows attackers to run their own code on the server. This can happen if the server settings are misconfigured, allowing an attacker to change the path to a PHP interpreter. To stay secure, update the Xerte Online Tools to the latest version.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| xerte | xerte online tools |
< v3.15.5 < 3.14.6 |
Original title
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PH...
Original description
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.
Vulnerability type
CWE-94
Code Injection
Published: 9 Jul 2026 · Updated: 20 Jul 2026 · First seen: 9 Jul 2026