CVE-2026-8208: High severity Gibbon Gibbon vulnerability
Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user provided .zip as PHP. Successful exploitation requires Teacher or higher privileges. Exploitation could result in compromise of the underlying web server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Gibbonto a version that resolves this vulnerability.Fixed in v30.0.01
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8208?
CVE-2026-8208 is a critical vulnerability that allows for remote code execution through local file inclusion.
How do I fix CVE-2026-8208?
To mitigate CVE-2026-8208, upgrade to Gibbon version 30.0.01 or later.
Who is affected by CVE-2026-8208?
CVE-2026-8208 affects Gibbon versions before v30.0.01 and requires Teacher privileges or higher for exploitation.
What can be the impact of exploiting CVE-2026-8208?
Exploitation of CVE-2026-8208 can lead to unauthorized remote code execution on the affected system.
Is there a workaround for CVE-2026-8208?
There are no known effective workarounds for CVE-2026-8208; updating to the patched version is recommended.