CVE-2026-26699

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
02/03/2026
Last modified:
04/03/2026

Description

sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin_change_picture.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jon-remus-sevellejo:personnel_property_equipment_system:1.0:*:*:*:*:*:*:*