CVE-2026-71624

An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components

  • Published Sep 4, 2026
  • CVSS 9.8 critical
  • 0.9% chance of exploitation in the next 30 days (EPSS)

CVE-2026-71624 at the National Vulnerability Database