CVE-2026-89308: Arbitrary command execution in TrxTimeATTENDANCE
Published Sep 15, 2026
·Updated
An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.
Affected Software
1 affected component
TrxTimeATTENDANCE
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TrxTimeATTENDANCEto a version that resolves this vulnerability.Fixed in 1.9.6
Event History
Sep 15, 2026
CVE Published
via MITRE·11:44 AM
Data Sourced
via MITRE·11:44 AM
RemedyDescriptionWeakness
Frequently Asked Questions
1
Does exploitation require authentication?
No. The vulnerability is described as unauthenticated, so a remote attacker does not need valid credentials to target the affected endpoint.
2
Can affected versions or configurations be identified from the available information?
No affected version range, fixed version, or configuration prerequisite is provided. The available information identifies ping.php as the vulnerable endpoint but does not specify which releases include it.