CVE-2026-63722

Source
https://cve.org/CVERecord?id=CVE-2026-63722
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63722.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63722
Published
2026-08-19T19:13:45.090Z
Modified
2026-08-21T03:46:56.519088389Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.php
Details

ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP POST request to the terminal endpoint with a password parameter to bypass authentication, a non-empty csrf parameter to skip CSRF validation, and an arbitrary command string passed directly to proc_open() to achieve remote code execution as the web-server user.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63722.json"
}
References

Affected packages

Git / github.com/icecoder/icecoder

Affected ranges

Type
GIT
Repo
https://github.com/icecoder/icecoder
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "8.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

7.*
7.0
7.0beta
8.*
8.0
8.0beta
v0.*
v0.5.9
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.6.7
v0.6.8
v0.6.9
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.7.5
v0.7.6
v0.7.7
v0.7.8
v0.7.9
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.4
v0.8.5
v0.8.6
v0.9.0
v0.9.1
v1.*
v1.0.0
v1.1
v1.2
v1.3
v1.4
v1.5
v1.6
v2.*
v2.0
v2.0beta
v2.1
v2.2
v2.3
v2.4
v2.5
v3.*
v3.0
v3.0beta
v3.1
v3.2
v3.3
v3.4
v3.5
v4.*
v4.0
v4.0beta
v4.1
v4.2
v4.3
v4.4
v4.5
v5.*
v5.0
v5.0beta
v5.1
v5.2
v5.3
v5.4
v5.5
v5.6
v5.7
v6.*
v6.0
v6.0beta

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63722.json"