cvefeed.io Critical RCE Vulnerability in WebErpMesv2 Affects Self-Registered Users
Article Content
- •CVE-2026-49827 allows unauthenticated RCE via PHP file uploads in WebErpMesv2.
- •The vulnerability is critical, with a CVSS score of 9.8, affecting versions 1.19 and prior.
- •Immediate patching and access control measures are recommended to mitigate risks.
CVE-2026-49827, published on August 13, 2026, reveals a critical vulnerability in WebErpMesv2 versions 1.19 and prior. This flaw allows unauthenticated remote code execution through arbitrary PHP file uploads via the HR Expense scan_file parameter. The vulnerability is exacerbated by open user registration and broken role middleware, enabling any self-registered user to exploit it. Attackers can execute arbitrary code with the privileges of the web application process. The issue has been patched in commit 5c54862fa044b363fd2be03d586750e81afd6818. Security experts recommend upgrading to a patched version and implementing strict access controls and file upload validations. The CVSS base score for this vulnerability is 9.8, indicating a severe threat level. Currently, there are no public proof-of-concept exploits or confirmed instances of exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-49827 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…