Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/apioo/fusio |
|
Tue, 11 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute arbitrary OS commands by exploiting a PHP-Sandbox allow-list bypass. The sandbox allow-list permits functions that transitively invoke system(), enabling a developer to escape the sandbox and gain OS command execution on the server. An attacker with a Developer-role account can achieve full server compromise. | |
| Title | Apioo Fusio - Remote Code Execution | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T15:13:19.293Z
Reserved: 2026-08-10T10:32:49.081Z
Link: CVE-2026-72551
Updated: 2026-08-11T15:13:15.338Z
Status : Received
Published: 2026-08-11T12:17:40.733
Modified: 2026-08-11T16:17:35.463
Link: CVE-2026-72551
No data.
OpenCVE Enrichment
Updated: 2026-08-11T17:15:06Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')