SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-14261

CRITICAL · CVSS 9.1 EPSS 0.85% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

A critical vulnerability in Xerte Online Tools allows attackers to bypass authentication and execute remote code by exploiting the /setup/ folder, potentially leading to the reinstallation of the service on a malicious database. Organizations using Xerte Online Tools should prioritize immediate remediation to prevent unauthorized access and control over their systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-14261
Severity
CRITICAL
CVSS
9.1
EPSS
0.85%

Original NVD Description

A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control.