Arbitrary File Upload Vulnerability in BorG Technology's Borg SPM 2007
CVE-2026-6885

9.3CRITICAL

Key Information:

Vendor
CVE Published:
23 April 2026

What is CVE-2026-6885?

The Borg SPM 2007 software developed by BorG Technology Corporation is vulnerable to an arbitrary file upload flaw. This vulnerability allows unauthenticated remote attackers to upload malicious files, potentially enabling them to deploy web shell backdoors. By exploiting this weakness, attackers can execute arbitrary code on the server, compromising the confidentiality, integrity, and availability of the system.

Affected Version(s)

Borg SPM 2007 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.