{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/icecoder-8.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-63722"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ICEcoder (8.1)"],"_cs_severities":["critical"],"_cs_tags":["web-application-vulnerability","rce","cve-2026-63722"],"_cs_type":"advisory","_cs_vendors":["ICEcoder"],"content_html":"\u003cp\u003eICEcoder version 8.1 is affected by a critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2026-63722. This vulnerability stems from inadequate input validation and security control implementation within the application's terminal functionality. An attacker can exploit this flaw by sending a specially crafted HTTP POST request to the terminal endpoint. By providing a password parameter, the attacker bypasses the authentication mechanism; by including a non-empty CSRF parameter, they circumvent CSRF protection. Finally, the application passes the attacker-supplied command string directly into the PHP proc_open() function. This allows the execution of arbitrary OS commands with the privileges of the web-server process, potentially leading to full server compromise. Given the ease of exploitation, immediate remediation is required for all deployments of ICEcoder 8.1.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify a target web server running ICEcoder 8.1.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the application's terminal endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker includes a 'password' parameter in the POST body to bypass initial authentication checks.\u003c/li\u003e\n\u003cli\u003eAttacker includes a non-empty 'csrf' parameter to satisfy the application's CSRF validation logic.\u003c/li\u003e\n\u003cli\u003eAttacker provides the malicious payload within the command parameters destined for the terminal execution flow.\u003c/li\u003e\n\u003cli\u003eThe application processes the request, failing to sanitize the command input.\u003c/li\u003e\n\u003cli\u003eThe application invokes the underlying PHP proc_open() function with the attacker-controlled input.\u003c/li\u003e\n\u003cli\u003eArbitrary OS commands execute in the context of the web-server user, resulting in system impact.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-63722 grants an unauthenticated attacker full remote code execution capabilities on the host server. This allows for data exfiltration, lateral movement within the network, or the installation of persistent backdoors. The impact is assessed as critical, given the ease of triggering the RCE via a single unauthenticated HTTP request.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately upgrade all instances of ICEcoder to a patched version once available to address CVE-2026-63722.\u003c/li\u003e\n\u003cli\u003eImplement WAF rules to inspect HTTP POST requests targeting the ICEcoder terminal endpoint for command injection patterns (e.g., shell operators like ';', '|', '\u0026amp;\u0026amp;').\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect attempts to access the terminal endpoint with known bypass parameters.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-19T20:39:22Z","date_published":"2026-08-19T20:39:22Z","id":"https://feed.craftedsignal.io/briefs/2026-08-icecoder-rce/","summary":"ICEcoder version 8.1 contains a critical vulnerability allowing unauthenticated remote code execution via a crafted HTTP POST request to the terminal endpoint that chains authentication and CSRF bypasses.","title":"Unauthenticated Remote Code Execution in ICEcoder 8.1","url":"https://feed.craftedsignal.io/briefs/2026-08-icecoder-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - ICEcoder (8.1)","version":"https://jsonfeed.org/version/1.1"}