Arbitrary File Upload Vulnerability in DMP-5000 File Service by DMP Technologies
CVE-2026-33560

8.4HIGH

Key Information:

Vendor

Daktronics

Vendor
CVE Published:
26 June 2026

What is CVE-2026-33560?

The DMP-5000 file service presents a significant security flaw by allowing authenticated users to upload files of any type without proper validation. This vulnerability exposes multiple endpoints, enabling unauthorized file uploads that bypass essential security measures such as file extension filtering and content inspection. As a result, attackers could upload executable binaries and scripts directly to the server, potentially compromising its integrity and enabling further exploitation.

Affected Version(s)

DMP-5000 0

DMP-5000 0

DMP-5000 0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thomas Jou of Princeton University reported this vulnerability to CISA.
.