Input validation error in Flag attendance field - CVE-2026-55809

 

Input validation error in Flag attendance field - CVE-2026-55809

Published: June 18, 2026


Vulnerability identifier: #VU134779
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55809
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to the PHP object injection issue in flag_attendance_field. A remote user can execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Flag attendance field

How to mitigate CVE-2026-55809

Install updates from vendor's website.

Flag attendance field - update to 1.2

External References

Related Security Bulletins