CVE-2026-18969: Rongzhitong Visual Integrated Command and Dispatch Platform upload unrestricted upload
A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing a manipulation of the argument File results in unrestricted upload. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18969?
CVE-2026-18969 has a high severity rating of 7.3.
What type of vulnerability is CVE-2026-18969?
CVE-2026-18969 is classified as a malicious file upload vulnerability.
How does CVE-2026-18969 impact the Rongzhitong platform?
CVE-2026-18969 allows for unrestricted file uploads, potentially compromising the system.
How can I mitigate CVE-2026-18969?
Mitigation for CVE-2026-18969 involves validating and sanitizing file uploads to prevent malicious content.
When was CVE-2026-18969 published?
CVE-2026-18969 was published on August 5, 2026.