External risk intelligence

WookTeam RCE via Project Task Export Interface

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-88393

The vulnerability exists in a project task export API endpoint of a web application. Such API endpoints in collaboration and project management software are commonly exposed as internet-facing services to facilitate remote access for users, making them reachable in typical deployment patterns.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in the WookTeam application's project task export feature, allowing unauthenticated attackers to execute arbitrary code remotely. This issue arises from the improper handling of user-supplied data within an export function, which can be exploited to compromise the underlying system. The primary concern is to determine if this specific application is in use and exposed to external access.

  • Allows remote code execution via export function.
  • Critical flaw could impact system integrity and operations.
  • Confirm if the affected product is in use and exposed.

Attack Path

How an attacker could exploit the issue

An attacker could target the project task export interface of WookTeam, a feature that allows users to export project tasks. By sending a specially crafted request containing base64-encoded data, an attacker can trick the application into executing arbitrary PHP code, leading to remote code execution on the server.

  • No authentication required.
  • Exploits task export interface.
  • Results in arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

WookTeam's project task export interface could allow an unauthenticated attacker to execute arbitrary PHP code on the server. This could occur when the `data` parameter, when base64-decoded, begins with `array`, triggering an `eval()` function with user-supplied input. The outcome is remote code execution, which could affect system data or behavior.

  • Server-side code execution.
  • Unauthenticated remote injection via API.
  • Compromise of server and its data.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WookTeam application, specifically its project task export interface, is susceptible to remote code execution. Given this is a web application API, responsibility likely falls to the application owners and platform or infrastructure teams who manage its deployment and exposure. The initial practical step is to determine the extent of the deployment, assess its reachability and criticality, and identify the accountable owner to plan a risk-based remediation.

  • Application owners and platform teams.
  • Verify external reachability and critical assets.
  • Plan remediation based on asset criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is WookTeam?

WookTeam is a project management and collaboration software platform. It is designed to help teams organize tasks, manage projects, and communicate effectively within a shared digital workspace. Organizations typically host this application on their own servers to centralize task tracking and project workflows.

What does CWE-94 mean for CVE-2026-88393?

CWE-94 refers to Improper Control of Generation of Code. In the context of this CVE, it means the application takes input from a user and processes it in a way that allows the system to inadvertently execute that input as programming code. Because the software uses an unsafe function to handle task export data, it accidentally interprets malicious input as instructions to run arbitrary PHP commands.

How is this vulnerability triggered?

An attacker triggers this by sending a crafted request to the task export API with specific base64-encoded data. The vulnerability only occurs when the decoded data begins with the word 'array', which causes the application's underlying code to pass the input into an evaluation function. Requests that do not follow this specific structure or trigger this particular function will not result in code execution.

Is my instance of WookTeam at risk?

According to Halo Surface Signal, this vulnerability is considered a concern if your instance is internet-facing. Because this software is often used for remote collaboration, these task export endpoints are frequently exposed to the public internet to facilitate access. If your installation is accessible from outside your internal network, it is more likely to be reachable by unauthorized parties.

How should I respond to this threat?

The first step is to identify all instances of WookTeam within your environment. Once identified, confirm whether they are internet-facing or restricted to internal users. Locate the owners of these applications and assess the criticality of the data they manage. Use this information to prioritize the application for security updates or isolation measures until you can apply a vendor-provided fix.

References