Vulnerability Description
A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control.
CVSS Score
CRITICAL
References
- https://github.com/thexerteproject/xerteonlinetoolkits/commit/8fec6602e80c5d3590
- https://github.com/thexerteproject/xerteonlinetoolkits/issues/1532
- https://www.xerte.org.uk/index.php/en/news/blog/80-news/364-xerte-3-14-and-3-15-
FAQ
What is CVE-2026-14261?
CVE-2026-14261 is a vulnerability with a CVSS score of 9.1 (CRITICAL). A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a rem...
How severe is CVE-2026-14261?
CVE-2026-14261 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-14261?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.