AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-67243

HIGH · CVSS 7.2 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The freo2 product by refirio is vulnerable due to an unrestricted file upload flaw, allowing users with administrative privileges to upload and execute malicious executable files. This could lead to arbitrary command execution on the operating system, posing a significant security risk. Organizations using this product should prioritize remediation to prevent potential exploitation by attackers.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67243
Severity
HIGH
CVSS
7.2
EPSS
0.30%

Original NVD Description

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.