SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-24727

CRITICAL · CVSS 9.3 EPSS 0.67%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

The SUNNET Corporate Training Management System's e-paper draft upload function is vulnerable to unrestricted file uploads, allowing remote authenticated users with administrator privileges to upload a malicious ZIP archive containing executable files. This vulnerability could lead to arbitrary command execution on the server, posing a significant risk to system integrity and data security. Organizations using this system, especially those with administrative access, should prioritize patching this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-24727
Severity
CRITICAL
CVSS
9.3
EPSS
0.67%

Original NVD Description

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.