Skip to content
Critical RCE Vulnerability in WebErpMesv2 Affects Self-Registered Users

Critical RCE Vulnerability in WebErpMesv2 Affects Self-Registered Users

First seen 14 Aug 2026, 01:14 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 15, 2026 at 00:45 UTC
  • •CVE-2026-49827 allows unauthenticated RCE via PHP file uploads in WebErpMesv2.
  • •The vulnerability is critical, with a CVSS score of 9.8, affecting versions 1.19 and prior.
  • •Immediate patching and access control measures are recommended to mitigate risks.

CVE-2026-49827, published on August 13, 2026, reveals a critical vulnerability in WebErpMesv2 versions 1.19 and prior. This flaw allows unauthenticated remote code execution through arbitrary PHP file uploads via the HR Expense scan_file parameter. The vulnerability is exacerbated by open user registration and broken role middleware, enabling any self-registered user to exploit it. Attackers can execute arbitrary code with the privileges of the web application process. The issue has been patched in commit 5c54862fa044b363fd2be03d586750e81afd6818. Security experts recommend upgrading to a patched version and implementing strict access controls and file upload validations. The CVSS base score for this vulnerability is 9.8, indicating a severe threat level. Currently, there are no public proof-of-concept exploits or confirmed instances of exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 48d ago How this analysis works

Timeline

2026-08-13
CVE-2026-49827 published
CVE-2026-49827 details a critical RCE vulnerability in WebErpMesv2 affecting versions 1.19 and prior.
cvefeed.io
2026-08-13
Patch released for CVE-2026-49827
A patch for the vulnerability was made available in commit 5c54862fa044b363fd2be03d586750e81afd6818.
Feedly
Recent
No public proof-of-concept found
As of the latest reports, there is no evidence of public proof-of-concept exploits for this vulnerability.
Feedly

More articles in this cluster (4)

Following this threat?

Track CVE-2026-49827 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed