OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE).
References
| Link | Resource |
|---|---|
| https://github.com/hungnqdz/CVE-2026-26746/blob/main/CVE-2026-26746.md | Exploit Mitigation Third Party Advisory |
| https://github.com/opensourcepos/opensourcepos | Product |
Configurations
History
24 Feb 2026, 20:42
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Opensourcepos
Opensourcepos open Source Point Of Sale |
|
| Summary |
|
|
| References | () https://github.com/hungnqdz/CVE-2026-26746/blob/main/CVE-2026-26746.md - Exploit, Mitigation, Third Party Advisory | |
| References | () https://github.com/opensourcepos/opensourcepos - Product | |
| CPE | cpe:2.3:a:opensourcepos:open_source_point_of_sale:3.4.1:*:*:*:*:*:*:* |
23 Feb 2026, 21:19
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| CWE | CWE-434 |
20 Feb 2026, 17:25
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-20 17:25
Updated : 2026-02-24 20:42
NVD link : CVE-2026-26746
Mitre link : CVE-2026-26746
CVE.ORG link : CVE-2026-26746
JSON object : View
Products Affected
opensourcepos
- open_source_point_of_sale
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
