CVE-2026-1061 identifies a critical unrestricted file upload vulnerability affecting xiweicheng TMS (teamwork_management_system) up to version 2.28.0. This flaw, residing in the 'Upload' function of 'FileController.java', allows a remote attacker to manipulate the 'filename' argument, enabling arbitrary file uploads. With a CVSS score of 9.8 Critical, this vulnerability permits unauthenticated attackers to achieve complete compromise of system confidentiality, integrity, and availability with low attack complexity. Although not currently listed on CISA's Known Exploited Vulnerabilities catalog, public exploit code is available, significantly increasing the immediate risk of exploitation despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.28.0CPE matchmatch criteria | cpe:2.3:a:xiweicheng:teamwork_management_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.