File Upload Vulnerability in TMS by TopTech
CVE-2026-70356

9.4CRITICAL

Key Information:

Vendor
CVE Published:
29 September 2026

What is CVE-2026-70356?

The file upload functionality in TMS does not adequately validate the types of files being uploaded. This weakness enables an attacker to upload and potentially execute malicious PHP files on the server, which could lead to unauthorized access or control over the affected web application. It is crucial for users to apply security updates and review file upload validation mechanisms to mitigate these risks.

Affected Version(s)

TMS7 7.6.3

TopHAT 7.6.3

TMS7 7.8

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sachin Shetty and Roy Duisters of Shell CyberDefence reported this vulnerability to Toptech and CISA.
.