Data Export Vulnerability in TMS7 Product by TopTech
CVE-2026-71379

10CRITICAL

Key Information:

Vendor
CVE Published:
29 September 2026

What is CVE-2026-71379?

A security flaw exists in the TMS7 product by TopTech, where the file export endpoint is susceptible to exploitation. This issue allows unauthenticated attackers to export arbitrary database tables simply by issuing a specially crafted POST request. The vulnerability raises significant concerns regarding data integrity and unauthorized access to sensitive information, making it essential for users to apply necessary countermeasures to secure their systems.

Affected Version(s)

TMS7 7.6.3

TopHAT 7.6.3

TMS7 7.8

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sachin Shetty and Roy Duisters of Shell CyberDefence reported this vulnerability to Toptech and CISA.
.