Skip to content
COOEY

FAIL › dossier

iCagenda

VENDOR

· dossier confidence 50%

iCagenda is a SaaS scheduling platform with a critical security vulnerability in 2026 that allowed remote code execution via arbitrary file uploads. The company failed to patch this high-severity RCE0day for over a month, exposing its attachment feature to exploitation.

PROFILE
CategorySaaSWhat they doiCagenda is a SaaS scheduling and event management platform.
SECURITY POSTURE

iCagenda has a poor security posture, evidenced by a critical RCE0day vulnerability in 2026 that remained unpatched for over a month, allowing arbitrary file uploads and PHP code execution via its attachment feature.

Notable failures
  • CVE-2026-48939: Arbitrary file upload leading to PHP RCE via attachments
Patterns: unpatched critical RCE vulnerabilities; insecure attachment handling
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2026-07-10 CVE-2026-48939 high iCagenda allows arbitrary file uploads leading to PHP code execution via its attachment feature.
2026-07-10 CVE-2026-48939 high iCagenda allows arbitrary file uploads leading to PHP code execution via its attachment feature.
2026-06-20 CVE-2026-48939 critical A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Open questions: When was CVE-2026-48939 patched? · What was the impact of the RCE0day on iCagenda's customers?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-17 03:54:35.969412+00:00