OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-88738

HIGH · CVSS 8.8 EPSS 0.61% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Jazzware RT1000 Edge webUI version 20.0.1 is vulnerable due to an unrestricted file upload feature that allows authenticated attackers to upload executable files. These files are stored in a publicly accessible location, enabling remote code execution without further authentication. Organizations using this version should prioritize addressing this vulnerability to mitigate the risk of unauthorized access and potential system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88738
Severity
HIGH
CVSS
8.8
EPSS
0.61%

Original NVD Description

Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.