CVE-2026-89308
An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.
- Published Sep 15, 2026
- CVSS 9.3 critical
- 2.1% chance of exploitation in the next 30 days (EPSS)