CVE WATCH / VULNERABILITY DETAIL
CVE-2026-88393
UNKNOWNCVSS 0NVD feed
Published 5 October 2026 · tracked since 5 October 2026
Description
WookTeam v1.6.6 and before is vulnerable to RCE in the project task export interface /api/project/task/export. The data parameter is base64-decoded and passed directly into the string2array() function in app/Module/Base.php, which executes eval("\$array = $data;") whenever the decoded string starts
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-102779
- CVE-2026-102777
- CVE-2026-102282 HIGH 7.1
- CVE-2026-88396
- CVE-2026-105329 MEDIUM 6.3
- CVE-2026-105397 MEDIUM 5.4
- CVE-2026-104890 HIGH 7.2
- CVE-2026-102426
- CVE-2026-102428
- CVE-2026-102775