CVE-2026-70356: Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type
The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Toptech TMS7 and TopHATto a version that resolves this vulnerability.Fixed in 7.8
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs high privileges and network access to the affected system. No user interaction is required, and the attack complexity is rated low.
What is the potential impact after successful exploitation?
Successful exploitation can result in high impact to confidentiality, integrity, and availability. The scope is changed, indicating the impact can extend beyond the initially vulnerable component.
Which deployments should be prioritized for review?
Review deployments of Toptech TMS7 and Toptech TopHAT, particularly systems where privileged users can access the TMS file upload endpoint over the network.