CVE-2026-1358

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.
Configurations

No configuration.

History

03 Mar 2026, 21:15

Type Values Removed Values Added
References
  • () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-044.txt -
Summary
  • (es) Airleader Master versiones 6.381 y anteriores permiten la carga de archivos sin restricción a múltiples páginas web ejecutándose con privilegios máximos. Esto podría permitir a un usuario no autenticado obtener potencialmente la ejecución remota de código en el servidor.

17 Feb 2026, 19:21

Type Values Removed Values Added
References
  • () https://airleader.us/contact/ -

12 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 22:16

Updated : 2026-03-03 21:15


NVD link : CVE-2026-1358

Mitre link : CVE-2026-1358

CVE.ORG link : CVE-2026-1358


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type