FAIL › dossier
iCagenda
VENDOR· dossier confidence 50%
iCagenda is a SaaS scheduling platform with a critical security vulnerability in 2026 that allowed remote code execution via arbitrary file uploads. The company failed to patch this high-severity RCE0day for over a month, exposing its attachment feature to exploitation.
PROFILE
CategorySaaSWhat they doiCagenda is a SaaS scheduling and event management platform.
SECURITY POSTURE
iCagenda has a poor security posture, evidenced by a critical RCE0day vulnerability in 2026 that remained unpatched for over a month, allowing arbitrary file uploads and PHP code execution via its attachment feature.
Notable failures
- CVE-2026-48939: Arbitrary file upload leading to PHP RCE via attachments
Patterns: unpatched critical RCE vulnerabilities; insecure attachment handling
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-07-10 | CVE-2026-48939 | high | iCagenda allows arbitrary file uploads leading to PHP code execution via its attachment feature. |
| 2026-07-10 | CVE-2026-48939 | high | iCagenda allows arbitrary file uploads leading to PHP code execution via its attachment feature. |
| 2026-06-20 | CVE-2026-48939 | critical | A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. |
Open questions: When was CVE-2026-48939 patched? · What was the impact of the RCE0day on iCagenda's customers?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-17 03:54:35.969412+00:00