CVE-2026-89308
Arbitrary command execution in TrxTimeATTENDANCE
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.
| CWE | CWE-78 |
| Vendor | trexom |
| Product | trxtimeattendance |
| Published | Sep 15, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for trexom trxtimeattendance
Be the first to know when new unknown vulnerabilities affecting trexom trxtimeattendance are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
TREXOM / TrxTimeATTENDANCE
1.0.5 < 1.9.6
References
Credits
@VolpinaRegina CSIRT-IT