CVE-2026-26746

OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE).
Configurations

Configuration 1 (hide)

cpe:2.3:a:opensourcepos:open_source_point_of_sale:3.4.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-20 17:25

Updated : 2026-02-24 20:42


NVD link : CVE-2026-26746

Mitre link : CVE-2026-26746

CVE.ORG link : CVE-2026-26746


JSON object : View

Products Affected

opensourcepos

  • open_source_point_of_sale
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type