CVE-2026-80233: CAYIN Technology|CAYIN CMS-WS/CMS-SE/SMP - Arbitrary File Upload
CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shells backdoors, thereby enabling arbitrary code execution on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CAYIN CMS-SEto a version that resolves this vulnerability.Fixed in 11.0.26198 - Upgrade
Upgrade
CAYIN CMS-WSto a version that resolves this vulnerability.Fixed in 1.0.26198 - Upgrade
Upgrade
CAYIN SMPto a version that resolves this vulnerability.Fixed in 4.0.26198
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be remote and already hold privileged access to the affected CAYIN CMS-WS, CMS-SE, or SMP product. No user interaction is required.
What is the impact of successful exploitation?
A privileged attacker can upload and execute a web-shell backdoor, resulting in arbitrary code execution on the server. The listed impact includes high confidentiality, integrity, and availability effects.
Are default deployments known to be affected?
The available information identifies affected product families but does not state whether the vulnerable upload functionality is enabled or reachable in default configurations.