← back

CVE-2026-89308

hype MIXED · 42 hack

Real vuln, same-day publication, but no KEV, PoC, vendor patch, or defender confirmation yet. Syndicated chatter pattern.

What: Unauthenticated OS command injection in TrxTimeAttendance ping.php endpoint (versions 1.0.5–1.9.5) enabling remote code execution. CVSS reported as 9.3 in social posts, though NVD lists n/a.

Why it matters: Published today with immediate social amplification flagging RCE risk in widely-deployed time-attendance software. No KEV listing yet; no confirmed public PoC or active exploitation reported. Chatter emphasizes "patch or restrict access now" but lacks defender triage feedback or vendor advisory confirmation.

Where it's seen: Same-day coordinated posts across Bluesky citing CVSS 9.3 and urging immediate mitigation. References to threat intelligence aggregators (stackflag, stemshop, offseq, radar) indicate rapid feed syndication rather than organic discovery.

RISK: HIGH — Unauthenticated RCE in time-attendance systems with broad deployment surface; unpatched versions 1.0.5–1.9.5.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/15/2026, 5:33:08 PM

Description

An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.

Weaknesses