File Upload Vulnerability in Başarsoft Rotaban Product
CVE-2026-11839

9.9CRITICAL

What is CVE-2026-11839?

A vulnerability in Başarsoft Information Technologies Inc.'s Rotaban allows for unrestricted file uploads of harmful types, potentially enabling attackers to upload a web shell onto the server. This issue is present in Rotaban versions up to and including V2026.06.002, impacting the application's security integrity by providing malicious users with unauthorized access to execute scripts and control server functions.

Affected Version(s)

Rotaban V2026.06.002

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mehmet MURAT
.