CVE-2026-1358

Szczegóły podatności CVE.
Aktualizacja: 04.03.2026, 01:54 (CET)
non-KEV CVSS 9.8 EPSS 0.0015 Score 29.49

Airleader Master versions 6.381 and prior allow for file uploads without
restriction to multiple webpages running maximum privileges. This could
allow an unauthenticated user to potentially obtain remote code
execution on the server.

Źródła

ŹródłoLinkUwagi
NVD (NIST)https://nvd.nist.gov/vuln/detail/CVE-2026-1358Karta CVE w NVD
CISA KEVhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-1358Wyszukiwanie CVE w KEV
FIRST EPSShttps://api.first.org/data/v1/epss?cve=CVE-2026-1358API EPSS dla CVE
ics-cert@hq.dhs.govhttps://airleader.us/contact/NVD Reference
ics-cert@hq.dhs.govhttps://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-043-10.jsonNVD Reference
ics-cert@hq.dhs.govhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-043-10NVD Reference
ics-cert@hq.dhs.govhttps://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-044.txtNVD Reference