Arbitrary File Upload Vulnerability in DMP-5000 File Service by DMP Technologies
CVE-2026-33560
8.4HIGH
What is CVE-2026-33560?
The DMP-5000 file service presents a significant security flaw by allowing authenticated users to upload files of any type without proper validation. This vulnerability exposes multiple endpoints, enabling unauthorized file uploads that bypass essential security measures such as file extension filtering and content inspection. As a result, attackers could upload executable binaries and scripts directly to the server, potentially compromising its integrity and enabling further exploitation.
Affected Version(s)
DMP-5000 0
DMP-5000 0
DMP-5000 0
References
CVSS V4
Score:
8.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thomas Jou of Princeton University reported this vulnerability to CISA.
