CVE-2026-26746 | Open Source Point of Sale 3.4.1 Configuration Sales.php getInvoice file inclusion
A vulnerability described as critical has been identified in Open Source Point of Sale 3.4.1. The impacted element is the function getInvoice of the file Sales.php of the component Configuration Handler. Such manipulation leads to file inclusion.
This vulnerability is documented as CVE-2026-26746. The attack can be executed remotely. There is not any exploit available.