CVE-2026-8208
gibbonedu gibbon
Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user provided .zip as PHP. Successful exploitation requires Teacher or higher privileges. Exploitation could result in compromise of the underlying web server.
- CVSS
- 8.9
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.05.09