Home

Description

OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE).

PUBLISHED Reserved 2026-02-16 | Published 2026-02-20 | Updated 2026-02-23 | Assigner mitre

References

github.com/opensourcepos/opensourcepos

github.com/...qdz/CVE-2026-26746/blob/main/CVE-2026-26746.md

cve.org (CVE-2026-26746)

nvd.nist.gov (CVE-2026-26746)

Download JSON