Junglewise Threat Intelligence

CVE-2026-12116: The Xerte Project Xerte Online Toolkits RCE via antivirus binary path configuration

CVE-2026-12116 · Severity: info · CVSS 9 · Published 2026-07-09

Technologies: The Xerte Project Xerte Online Toolkits. Vendors: The Xerte Project.

Executive brief

Xerte Online Toolkits, a platform for creating interactive learning materials, contains a security flaw in its server management settings. An attacker with administrative access can change the path of the system's antivirus software to point to a malicious script or a command interpreter. This allows the attacker to execute arbitrary code on the server, potentially leading to a full system takeover and the theft of sensitive educational data.

Technical details

A remote code execution (RCE) vulnerability exists in Xerte Online Toolkits due to insecure handling of the antivirus configuration path in the management interface. An attacker with sufficient privileges can modify the 'antivirus binary path' setting to point to a PHP interpreter or other executable. By subsequently uploading a file that triggers an antivirus scan, the attacker can force the server to execute the specified binary with the uploaded file as an argument, leading to arbitrary code execution. The fix involves moving this configuration out of the web-accessible management page to prevent unauthorized modification.

Affected products

  • The Xerte Project Xerte Online Toolkits Prior to 3.14 / 3.15

Timeline

  • 2026-06-17: disclosed: Issue reported via GitHub and CERT/CC VINCE
  • 2026-07-09: advisory: CVE published and security update announced

References

Related threats