📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Technology and Artificial Intelligence MEDIUM 1h Global general Technology and Artificial Intelligence HIGH 2h Global vulnerability Higher Education CRITICAL 11h Global data_breach Government HIGH 12h Global supply_chain Software Development and Open Source Communities CRITICAL 12h Global malware Software Development CRITICAL 12h Global phishing Multiple Sectors HIGH 12h Global vulnerability Web Applications CRITICAL 13h Global apt Critical Infrastructure CRITICAL 13h Global ransomware Multiple sectors CRITICAL 13h Global general Technology and Artificial Intelligence MEDIUM 1h Global general Technology and Artificial Intelligence HIGH 2h Global vulnerability Higher Education CRITICAL 11h Global data_breach Government HIGH 12h Global supply_chain Software Development and Open Source Communities CRITICAL 12h Global malware Software Development CRITICAL 12h Global phishing Multiple Sectors HIGH 12h Global vulnerability Web Applications CRITICAL 13h Global apt Critical Infrastructure CRITICAL 13h Global ransomware Multiple sectors CRITICAL 13h Global general Technology and Artificial Intelligence MEDIUM 1h Global general Technology and Artificial Intelligence HIGH 2h Global vulnerability Higher Education CRITICAL 11h Global data_breach Government HIGH 12h Global supply_chain Software Development and Open Source Communities CRITICAL 12h Global malware Software Development CRITICAL 12h Global phishing Multiple Sectors HIGH 12h Global vulnerability Web Applications CRITICAL 13h Global apt Critical Infrastructure CRITICAL 13h Global ransomware Multiple sectors CRITICAL 13h
Vulnerabilities

CVE-2026-27760

High
CWE-94 — Weakness Type
Published: Apr 28, 2026  ·  Modified: May 5, 2026  ·  Source: NVD
CVSS v3
8.1
🔗 NVD Official
📄 Description (English)

OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string context in config.php using a single quote and statement separator to inject malicious PHP code that persists and executes on every subsequent page load when the installation wizard remains incomplete.

🤖 AI Executive Summary

OpenCATS versions prior to commit 3002a29 contain an unauthenticated PHP code injection vulnerability in the installer AJAX endpoint that allows attackers to execute arbitrary code. The vulnerability persists in config.php and executes on every page load if the installation wizard remains incomplete.

📄 Description (Arabic)

تحتوي OpenCATS على ثغرة حقن كود PHP في نقطة نهاية AJAX للمثبت تسمح بتنفيذ كود عشوائي دون مصادقة. يمكن للمهاجمين الخروج من سياق سلسلة define() باستخدام علامة اقتباس واحدة وفاصل بيان لحقن كود PHP ضار. يستمر الكود المحقون في ملف config.php ويتم تنفيذه عند كل تحميل صفحة طالما ظل معالج التثبيت غير مكتمل.

🤖 ملخص تنفيذي (AI)

إصدارات OpenCATS السابقة للالتزام 3002a29 تحتوي على ثغرة حقن كود PHP غير مصرح بها في نقطة نهاية AJAX للمثبت تسمح للمهاجمين بتنفيذ كود عشوائي. تستمر الثغرة في ملف config.php وتنفذ عند كل تحميل صفحة إذا ظل معالج التثبيت غير مكتمل.

🤖 AI Intelligence Analysis Analyzed: May 3, 2026 13:17
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
government banking healthcare
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
9.0
/ 10.0
🔧 Remediation Steps (English)
Immediately upgrade OpenCATS to commit 3002a29 or later. Complete the installation wizard promptly to remove the vulnerable installer endpoint. Implement network-level access controls to restrict access to installer endpoints. Monitor config.php for unauthorized modifications and implement file integrity monitoring.
🔧 خطوات المعالجة (العربية)
قم بالترقية الفورية إلى الالتزام 3002a29 أو الإصدار الأحدث. أكمل معالج التثبيت بسرعة لإزالة نقطة النهاية الضعيفة. طبق عناصر تحكم في الوصول على مستوى الشبكة لتقييد الوصول إلى نقاط نهاية المثبت. راقب ملف config.php للتعديلات غير المصرح بها وطبق مراقبة سلامة الملفات.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A1 A2 A3
🔵 SAMA CSF
ID.BE-1 PR.AC-1 PR.PT-1
🟡 ISO 27001:2022
A.14.2.1 A.12.6.1 A.14.2.5
📊 CVSS Score
8.1
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityH — High
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.1
CWECWE-94
EPSS0.10%
Exploit No
Patch ✗ No
Published 2026-04-28
Source Feed nvd
🇸🇦 Saudi Risk Score
9.0
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-94
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.