Back to overview

CVE-2026-23836

CRITICAL
10.0
CVSS 3.1
Description
HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP formulas which allowed users to trigger the execution of arbitrary PHP code. The problem is patched in release version 3.2.

Metadata

CVE ID
CVE-2026-23836
State
PUBLISHED
Assigner
GitHub_M
Reserved
2026-01-16 15:46 UTC
Published
2026-01-19 18:06 UTC
Last updated
2026-01-20 21:40 UTC
Primary CWE
CWE-20
CWE-20: Improper Input Validation
Vendor / Product
kohler / hotcrp
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
kohler hotcrp = 3.1
Weakness (CWE)
CWESourceDescription
CWE-20 cna CWE-20: Improper Input Validation
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References (3)
Back to overview