cvefeed.io
Critical RCE Vulnerability in WebErpMesv2 Affects Self-Registered Users
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
CVE-2026-49827, published on August 13, 2026, reveals a critical vulnerability in WebErpMesv2 versions 1.19 and prior. This flaw allows unauthenticated remote code execution through arbitrary PHP file uploads via the HR Expense scan_file parameter. The vulnerability is exacerbated by open user registration and broken role middleware, enabling any self-registered user to exploit it. Attackers can execute arbitrary code with the privileges of the web application process. The issue has been patched in commit 5c54862fa044b363fd2be03d586750e81afd6818. Security experts recommend upgrading to a patched version and implementing strict access controls and file upload validations. The CVSS base score for this vulnerability is 9.8, indicating a severe threat level. Currently, there are no public proof-of-concept exploits or confirmed instances of exploitation.
Key Points: • CVE-2026-49827 allows unauthenticated RCE via PHP file uploads in WebErpMesv2. • The vulnerability is critical, with a CVSS score of 9.8, affecting versions 1.19 and prior. • Immediate patching and access control measures are recommended to mitigate risks.