{"id":"CVE-2026-70356","published":"2026-09-29T22:18:16.140","lastModified":"2026-09-29T22:18:16.140","description":"The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-434"],"vendors":[],"products":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","tags":[]},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","tags":[]},{"url":"https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","tags":[]}],"exploitRefs":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an attacker to upload and execute arbitrary PHP files, leading to remote code execution.","exploitability":"Exploitation is relatively easy as it requires an attacker to upload a malicious PHP file to the vulnerable endpoint.","blast_radius":"If exploited, the attacker could gain full control over the web server, leading to potential data theft or system compromise.","remediation":"Disable the file upload feature or restrict access to the affected endpoint.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","php","upload"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T08:58:28.780Z"}}