Arbitrary File Upload Vulnerability in CAYIN Technology CMS Products
CVE-2026-80233

8.6HIGH

Key Information:

Vendor
CVE Published:
26 August 2026

What is CVE-2026-80233?

CAYIN Technology’s CMS-WS, CMS-SE, and SMP series products are vulnerable to an arbitrary file upload issue. This vulnerability allows privileged remote attackers to upload files and execute backdoors, resulting in arbitrary code execution on the server. Attackers exploiting this flaw can manipulate the affected systems, posing a significant risk to security and data integrity. Users are encouraged to implement appropriate security measures to mitigate this risk.

Affected Version(s)

CAYIN CMS-SE 0 <= 11.0.25336

CAYIN CMS-WS 0 <= 1.0.25336

CAYIN SMP 0 <= 4.0.25336

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.