Unrestricted File Upload and Deserialization Vulnerability in Datavane TIS
CVE-2026-24815
10CRITICAL
What is CVE-2026-24815?
The Datavane TIS has a vulnerability that allows an attacker to upload malicious files due to improper validation of file types. This exposes the system to unauthorized file execution and potential data manipulation. Additionally, the vulnerability is exacerbated by the deserialization of untrusted data, which can lead to remote code execution or other malicious activities. This issue is present in versions of Datavane TIS before v4.3.0, making it essential for users to update to the latest version to mitigate the associated risks.
Affected Version(s)
tis 0
