Unrestricted File Upload and Deserialization Vulnerability in Datavane TIS
CVE-2026-24815

10CRITICAL

Key Information:

Vendor

Datavane

Status
Vendor
CVE Published:
27 January 2026

What is CVE-2026-24815?

The Datavane TIS has a vulnerability that allows an attacker to upload malicious files due to improper validation of file types. This exposes the system to unauthorized file execution and potential data manipulation. Additionally, the vulnerability is exacerbated by the deserialization of untrusted data, which can lead to remote code execution or other malicious activities. This issue is present in versions of Datavane TIS before v4.3.0, making it essential for users to update to the latest version to mitigate the associated risks.

Affected Version(s)

tis 0

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TITAN Team (titancaproject@gmail.com)
.