CVE-2026-89308 PUBLISHED

Arbitrary command execution in TrxTimeATTENDANCE

Assigner: ENISA
Reserved: 11.09.2026 Published: 15.09.2026 Updated: 15.09.2026

An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor TREXOM
Product TrxTimeATTENDANCE
Versions Default: unaffected
  • affected from 1.0.5 to 1.9.6 (excl.)

Workarounds

Block all HTTP requests to the ping.php endpoint at the web server or firewall level.

Solutions

Update to version 1.9.6

Credits

  • @VolpinaRegina finder
  • CSIRT-IT coordinator

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE

Impacts

  • CAPEC-88 OS Command Injection