Skip to content

CVE-2026-49827

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
August 13, 2026
Last Seen
August 14, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

CVE-2026-49827, published on August 13, 2026, reveals a critical vulnerability in WebErpMesv2 versions 1.19 and prior. This flaw allows unauthenticated remote code execution through arbitrary PHP file uploads via the HR Expense scan_file parameter. The vulnerability is exacerbated by open user regis...

Public Exploits

Checking GitHub for proof-of-concept code…