Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-38450: Aetopia DAM v1.0.0: Uncontrolled Code Execution via Project Fields
CVE-2026-38450
CVE-2026-38450
Summary
An attacker can use Aetopia Digital Asset Management DAM version 1.0.0 to run malicious code on a vulnerable server. This is a serious security risk because it could allow an attacker to access sensitive information or take control of the server. To stay secure, update to the latest version of Aetopia DAM.
Original title
An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function
Original description
An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function
Vulnerability type
CWE-94
Code Injection
Published: 14 Jul 2026 · Updated: 16 Jul 2026 · First seen: 14 Jul 2026