CVE-2026-26699: Code Injection
Published Mar 2, 2026
·Updated
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/adminchangepicture.php.
Affected Software
2 affected components
Sourcecodester Personnel Property Equipment System
Jon-remus-sevellejo Personnel Property Equipment System=1.0
Event History
Mar 2, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Jan 4, 58143
Event
via NVD·11:39 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-26699?
The severity of CVE-2026-26699 is high, with a CVSS score of 7.2.
2
What does CVE-2026-26699 affect?
CVE-2026-26699 affects the Sourcecodester Personnel Property Equipment System v1.0, specifically the admin_change_picture.php file.
3
How can I exploit CVE-2026-26699?
CVE-2026-26699 can be exploited through arbitrary code execution due to vulnerability in code injection.
4
How do I fix CVE-2026-26699?
To fix CVE-2026-26699, update to a patched version of the Sourcecodester Personnel Property Equipment System or implement appropriate code validation and sanitation.
5
What potential risks are associated with CVE-2026-26699?
CVE-2026-26699 poses a risk of arbitrary code execution, which can lead to unauthorized access and control over the system.