CVE-2026-33560
Received Received - Intake
Authenticated Arbitrary File Upload in DMP-5000 File Service

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: ICS-CERT

Description
The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-27
AI Q&A
2026-06-27
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability in the DMP-5000 file service allows authenticated users to upload files of any type without any validation.

There are exposed endpoints that do not enforce file extension filtering or content inspection, which means executable binaries and scripts can be uploaded and saved directly to the server.

Impact Analysis

This vulnerability can lead to serious security risks because attackers with valid credentials can upload malicious executable files or scripts.

These malicious files could be executed on the server, potentially leading to unauthorized code execution, system compromise, data breaches, or disruption of service.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33560. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart