What is CVE-2026-72551?
This is a remote code execution vulnerability in Apioo Fusio 8.8.3 where authenticated users with the Developer role can execute arbitrary OS commands via a PHP-sandbox allow-list bypass. Affected systems should be patched immediately or have sandbox allow-list rules tightened to block transitive system() calls.
Azərbaycanca: Bu zəiflik Apioo Fusio 8.8.3 platformasında Developer rolu olan autentifikasiya olunmuş istifadəçilərə PHP-sandbox allow-list bypass vasitəsilə ixtiyari OS əmrləri icra etməyə imkan verən remote code execution problemidir. Administratorlər dərhal verilən versiyanı yamalı və ya sandbox konfiqurasiyasında allow-list qaydalarını sərtləşdirməlidir.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Who can exploit CVE-2026-72551?
Only authenticated users with the Developer role in Apioo Fusio 8.8.3 can exploit this vulnerability.
What actions should be taken to mitigate CVE-2026-72551?
Administrators should immediately patch the affected Apioo Fusio 8.8.3 version or tighten the allow-list rules in the sandbox configuration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.