CVE-2026-88393
Received Received - Intake

Remote Code Execution in WookTeam Project Export

Vulnerability report for CVE-2026-88393, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: MITRE

Description

WookTeam v1.6.6 and before is vulnerable to RCE in the project task export interface /api/project/task/export. The data parameter is base64-decoded and passed directly into the string2array() function in app/Module/Base.php, which executes eval("\$array = $data;") whenever the decoded string starts with array. An attacker can inject arbitrary PHP code into the eval call and achieve RCE.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-88393 is a remote code execution (RCE) vulnerability in WookTeam versions 1.6.6 and earlier. It exists in the /api/project/task/export interface where user input is base64-decoded and passed to an eval() function without validation. The data parameter is processed by string2array() in app/Module/Base.php, which executes eval("$array = $data;") if the decoded string starts with 'array' but isn't exactly 'array'. This allows attackers to inject arbitrary PHP code for RCE.

Detection Guidance

To detect this vulnerability, monitor network traffic for requests to /api/project/task/export with base64-encoded data parameters. Check server logs for unusual eval() calls or PHP code execution attempts. Inspect app/Module/Base.php for the string2array() function and eval() usage with user-controlled input.

Impact Analysis

An attacker with a registered account can exploit this to execute arbitrary commands on the server. They can create projects, tasks, and trigger exports with malicious payloads. The vulnerability enables full system compromise, data theft, or installation of web shells for persistent access. It requires only basic user privileges and default public registration settings.

Compliance Impact

This RCE vulnerability could lead to unauthorized data access, modification, or exfiltration, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations using vulnerable WookTeam versions may face compliance violations, regulatory fines, and reputational damage due to potential data breaches.

Mitigation Strategies

Immediately upgrade WookTeam to a patched version beyond 1.6.6. Disable public registration if not required. Restrict access to /api/project/task/export to authenticated users only. Implement strict input validation for the data parameter to prevent base64-decoded code injection. Disable eval() usage entirely if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88393. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart