OpenCATS PHP Code Injection via installer AJAX endpoint
97Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.2epss 35%
from disclosure to weapon0 days
Published on NVDApr 28
metasploitApr 28
VulnCheck+50d
exploitation probability
35%top 2% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string context in config.php using a single quote and statement separator to inject malicious PHP code that persists and executes on every subsequent page load when the installation wizard remains incomplete.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
opencats · OpenCATSpublic PoCs found — 1
cve_referencechocapikk.com/posts/2026/opencats-installer-rce/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://chocapikk.com/posts/2026/opencats-installer-rce/https://github.com/opencats/OpenCATS/blob/46e4727/lib/CATSUtility.php#L142-L172https://github.com/opencats/OpenCATS/blob/46e4727/modules/install/ajax/ui.php#L130https://github.com/opencats/OpenCATS/commit/3002a29f4c3cada1aa2c4f3d4ae4e189906606b6https://github.com/opencats/OpenCATS/pull/706https://www.vulncheck.com/advisories/opencats-php-code-injection-via-installer-ajax-endpoint