Critical RCE Vulnerability in WebErpMesv2 Affects Self-Registered Users

Critical RCE Vulnerability in WebErpMesv2 Affects Self-Registered Users

First seen 14 Aug 2026, 01:14 UTC Feedlycvefeed.iowww.thehackerwire.comvuldb.com 87% similarity 72.6

Article Content

Browse articles
ThreatCluster

CVE-2026-49827, published on August 13, 2026, reveals a critical vulnerability in WebErpMesv2 versions 1.19 and prior. This flaw allows unauthenticated remote code execution through arbitrary PHP file uploads via the HR Expense scan_file parameter. The vulnerability is exacerbated by open user registration and broken role middleware, enabling any self-registered user to exploit it. Attackers can execute arbitrary code with the privileges of the web application process. The issue has been patched in commit 5c54862fa044b363fd2be03d586750e81afd6818. Security experts recommend upgrading to a patched version and implementing strict access controls and file upload validations. The CVSS base score for this vulnerability is 9.8, indicating a severe threat level. Currently, there are no public proof-of-concept exploits or confirmed instances of exploitation.

Key Points: • CVE-2026-49827 allows unauthenticated RCE via PHP file uploads in WebErpMesv2. • The vulnerability is critical, with a CVSS score of 9.8, affecting versions 1.19 and prior. • Immediate patching and access control measures are recommended to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-08-13
CVE-2026-49827 published
CVE-2026-49827 details a critical RCE vulnerability in WebErpMesv2 affecting versions 1.19 and prior.
cvefeed.io
2026-08-13
Patch released for CVE-2026-49827
A patch for the vulnerability was made available in commit 5c54862fa044b363fd2be03d586750e81afd6818.
Feedly
Recent
No public proof-of-concept found
As of the latest reports, there is no evidence of public proof-of-concept exploits for this vulnerability.
Feedly

Community

Browse all →

Tracked Entities in This Story