Remote Code Execution Vulnerability in Tencent Mass Service Engine
CVE-2026-89040
9.3CRITICAL
What is CVE-2026-89040?
A vulnerability in Tencent's Mass Service Engine (MSEC) allows an unauthenticated attacker to exploit the system by sending a specially crafted POST request. This can lead to unauthorized root access on the affected device. If an attacker successfully uploads a webshell, they can execute arbitrary code with root privileges, posing a significant risk to the integrity and security of the system.
Affected Version(s)
Mass Service Engine in Cluster (MSEC) 0
