🔐 CVE Alert

CVE-2026-89308

UNKNOWN 0.0

Arbitrary command execution in TrxTimeATTENDANCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.

CWE CWE-78
Vendor trexom
Product trxtimeattendance
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for trexom trxtimeattendance

Be the first to know when new unknown vulnerabilities affecting trexom trxtimeattendance are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

TREXOM / TrxTimeATTENDANCE
1.0.5 < 1.9.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
trexom.net: https://www.trexom.net/sviluppo-di-app/ acn.gov.it: https://www.acn.gov.it/portale/w/trexom-aggiornamenti-di-sicurezza

Credits

@VolpinaRegina CSIRT-IT