CVE-2026-25201: Malicious File Upload
Published Feb 2, 2026
·Updated
An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21.1090.1.
Affected Software
2 affected components
MagicInfo MagicINFO 9 Server<21.1090.1
Samsung MagicINFO 9 Server<21.1090.1
Event History
Feb 2, 2026
CVE Published
via MITRE·04:49 AM
Data Sourced
via MITRE·04:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-25201?
CVE-2026-25201 is classified as a high severity vulnerability due to its potential for remote code execution and privilege escalation.
2
What versions of MagicINFO are affected by CVE-2026-25201?
CVE-2026-25201 affects all versions of MagicINFO 9 Server prior to 21.1090.1.
3
How can I fix CVE-2026-25201?
To mitigate CVE-2026-25201, upgrade MagicINFO 9 Server to version 21.1090.1 or later.
4
What type of vulnerability is CVE-2026-25201?
CVE-2026-25201 is a file upload vulnerability that allows unauthenticated users to execute arbitrary code.
5
Can CVE-2026-25201 lead to data breaches?
Yes, CVE-2026-25201 can potentially lead to data breaches as it allows for remote code execution, enabling attackers to gain unauthorized access.