CVE-2026-16286: File Upload in TRTEK Software's Software Repository Management
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server.
This issue affects Software Repository Management: before 2fb4acee.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TRTEK Software Software Repository Managementto a version that resolves this vulnerability.Fixed in 2fb4acee
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability is rated AV:N/AC:L/PR:N/UI:N, indicating that it can be exploited remotely over the network with low attack complexity, without authentication or user interaction.
What is the impact if exploitation succeeds?
An attacker can upload a web shell to the web server. The reported CVSS vector indicates high potential impact to confidentiality, integrity, and availability.
Which deployments are affected?
Software Repository Management versions before 2fb4acee are affected. The supplied information does not state whether any particular default deployment configuration changes exposure.