CVE-2020-13638: rConfig

Critical severity, CVSS 9.8. EPSS: 76.6% chance of exploitation in the next 30 days.

lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7.

Affected products

  • rConfig rConfig: from 3.9.0, before 3.9.7 (fixed in 3.9.7)

Published 2020-11-13. Last modified 2026-06-17.