CVE-2026-89308
Real vuln, same-day publication, but no KEV, PoC, vendor patch, or defender confirmation yet. Syndicated chatter pattern.
What: Unauthenticated OS command injection in TrxTimeAttendance ping.php endpoint (versions 1.0.5–1.9.5) enabling remote code execution. CVSS reported as 9.3 in social posts, though NVD lists n/a.
Why it matters: Published today with immediate social amplification flagging RCE risk in widely-deployed time-attendance software. No KEV listing yet; no confirmed public PoC or active exploitation reported. Chatter emphasizes "patch or restrict access now" but lacks defender triage feedback or vendor advisory confirmation.
Where it's seen: Same-day coordinated posts across Bluesky citing CVSS 9.3 and urging immediate mitigation. References to threat intelligence aggregators (stackflag, stemshop, offseq, radar) indicate rapid feed syndication rather than organic discovery.
RISK: HIGH — Unauthenticated RCE in time-attendance systems with broad deployment surface; unpatched versions 1.0.5–1.9.5.
Description
An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.