CVE-2026-52610
Description
AI Translation Available
An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the 'saveTemplate' parameter in conjuction with 'execute_mode=PREPARE' parameter in the 'run.php' endpoint.
https://github.com/kilotel/vulnerability-research/tree/main/CVE-2026-52610
https://github.com/reportico-web/reportico