CVE-2026-27760 | OpenCATS up to 0.9.7.4 AJAX Endpoint config.php define action code injection (EUVD-2026-26052)
A vulnerability identified as critical has been detected in OpenCATS up to 0.9.7.4. This affects the function define of the file config.php of the component AJAX Endpoint. This manipulation of the argument action causes code injection.
This vulnerability is tracked as CVE-2026-27760. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to install a patch to address this issue.