CVE-2026-26746

OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE).
Configurations

Configuration 1 (hide)

cpe:2.3:a:opensourcepos:open_source_point_of_sale:3.4.1:*:*:*:*:*:*:*

History

24 Feb 2026, 20:42

Type Values Removed Values Added
First Time Opensourcepos
Opensourcepos open Source Point Of Sale
Summary
  • (es) OpenSourcePOS 3.4.1 contiene una vulnerabilidad de Inclusión Local de Ficheros (LFI) en la función Sales.php::getInvoice(). Un atacante puede leer ficheros arbitrarios en el servidor web manipulando la configuración de Tipo de Factura. Este problema puede encadenarse con la funcionalidad de subida de ficheros para lograr Ejecución Remota de Código (RCE).
References () https://github.com/hungnqdz/CVE-2026-26746/blob/main/CVE-2026-26746.md - () https://github.com/hungnqdz/CVE-2026-26746/blob/main/CVE-2026-26746.md - Exploit, Mitigation, Third Party Advisory
References () https://github.com/opensourcepos/opensourcepos - () https://github.com/opensourcepos/opensourcepos - Product
CPE cpe:2.3:a:opensourcepos:open_source_point_of_sale:3.4.1:*:*:*:*:*:*:*

23 Feb 2026, 21:19

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-434

20 Feb 2026, 17:25

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-20 17:25

Updated : 2026-02-24 20:42


NVD link : CVE-2026-26746

Mitre link : CVE-2026-26746

CVE.ORG link : CVE-2026-26746


JSON object : View

Products Affected

opensourcepos

  • open_source_point_of_sale
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type