CVE-2026-23836

CRITICAL

HotCRP <3.2 - RCE

Title source: llm
STIX 2.1

Description

HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP formulas which allowed users to trigger the execution of arbitrary PHP code. The problem is patched in release version 3.2.

Scores

CVSS v3 9.9
EPSS 0.0016
EPSS Percentile 36.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
hotcrp/hotcrp 3.0 - 3.2
Published Jan 19, 2026
Tracked Since Feb 18, 2026