{"id":"CVE-2026-89308","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-89308","summary":"An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and…","details":"An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.","published":"2026-09-15T12:17:53.603","modified":"2026-09-15T12:17:53.603","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.acn.gov.it/portale/w/trexom-aggiornamenti-di-sicurezza"},{"type":"WEB","url":"https://www.trexom.net/sviluppo-di-app/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-15T12:17:53.603"}}