← Back to search

CVE-2026-70356

9.1 CRITICALpublic exploit available

Published 2026-09-29 · Updated 2026-09-29

AI risk analysis

Summary
The flaw allows an attacker to upload and execute arbitrary PHP files, leading to remote code execution.
Exploitability
Exploitation is relatively easy as it requires an attacker to upload a malicious PHP file to the vulnerable endpoint.
Blast radius
If exploited, the attacker could gain full control over the web server, leading to potential data theft or system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the file upload feature or restrict access to the affected endpoint.
rcewebphpupload

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-434

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.