Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-24727: SUNNET Corporate Training Management System - Unrestricted File Upload Risk

CVE-2026-24727 · published 2 months ago
Summary

An attacker with admin privileges can upload malicious files, potentially allowing them to execute arbitrary commands on the system. This could lead to unauthorized access or system compromise. Users should ensure they are running the latest version of SUNNET Corporate Training Management System, and consider implementing additional security measures to restrict file uploads.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
sunnet technology co., ltd. corporate training management system <= v.10.3
Original advisory text
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users ...
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.
Severity
9.3 Critical
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published24 Jul 2026
Updated27 Sep 2026
First seen24 Jul 2026
Sources
CVE-2026-24727 · MITRE
Track software like this
Free during beta