CVE-2026-26746

O

penSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE).

Configurations

Configuration 1 (hide)

cpe:2.3:a:opensourcepos:open_source_point_of_sale:3.4.1:*:*:*:*:*:*:*

History

24 Feb 2026, 20:42

Type Values Removed Values Added
References () https://github.com/hungnqdz/CVE-2026-26746/blob/main/CVE-2026-26746.md - () https://github.com/hungnqdz/CVE-2026-26746/blob/main/CVE-2026-26746.md - Exploit, Mitigation, Third Party Advisory
References () https://github.com/opensourcepos/opensourcepos - () https://github.com/opensourcepos/opensourcepos - Product
CPE cpe:2.3:a:opensourcepos:open_source_point_of_sale:3.4.1:*:*:*:*:*:*:*
Summary
  • (es) OpenSourcePOS 3.4.1 contiene una vulnerabilidad de Inclusión Local de Ficheros (LFI) en la función Sales.php::getInvoice(). Un atacante puede leer ficheros arbitrarios en el servidor web manipulando la configuración de Tipo de Factura. Este problema puede encadenarse con la funcionalidad de subida de ficheros para lograr Ejecución Remota de Código (RCE).
First Time Opensourcepos
Opensourcepos open Source Point Of Sale

23 Feb 2026, 21:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-434

20 Feb 2026, 17:25

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-20 17:25

Updated : 2026-02-24 20:42


NVD link : CVE-2026-26746

Mitre link : CVE-2026-26746

CVE.ORG link : CVE-2026-26746


JSON object : View

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type