{"id":"CVE-2026-71379","published":"2026-09-29T22:18:21.560","lastModified":"2026-09-29T22:18:21.560","description":"The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.","cvssScore":10,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-552"],"vendors":[],"products":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","tags":[]},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","tags":[]},{"url":"https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","tags":[]}],"exploitRefs":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability allows unauthenticated attackers to export arbitrary database tables, posing a significant risk to data integrity and confidentiality.","exploitability":"Exploitation is relatively straightforward as it requires sending a crafted POST request, and no authentication is needed.","blast_radius":"If exploited, this could lead to unauthorized access to sensitive data, potentially compromising the entire database.","remediation":"Disable the file export endpoint or restrict access to it to only authenticated users.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["web","data-exposure","auth-bypass"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T08:44:55.969Z"}}