CVE-2026-89040: Tencent Mass Service Engine in Cluster (MSEC) path traversal
Published Sep 15, 2026
·Updated
Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.
Affected Software
1 affected component
Tencent Mass Service Engine in Cluster (MSEC)
Event History
Sep 15, 2026
CVE Published
via MITRE·08:05 PM
Data Sourced
via MITRE·08:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker does not need authentication or user interaction. The attack can be carried out by sending a crafted POST request containing ../ sequences to a vulnerable target.
2
What level of access can an attacker obtain?
Successful exploitation can provide root access on the target device. If the attacker uploads a webshell, they can execute arbitrary code as root.