CVE-2026-14261: Xerte Online Tools

Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.

A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control.

Affected products

  • Xerte Xerte Online Tools: before 3.14.6 (fixed in 3.14.6); before 3.15.5 (fixed in 3.15.5)

Published 2026-07-09. Last modified 2026-07-09.