CVE-2026-24727
Received Received - Intake

Unrestricted File Upload in SUNNET Corporate Training System

Vulnerability report for CVE-2026-24727, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: ZUSO Advanced Research Team (ZUSO ART)

Description

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sunnet corporate_training_management_system 10.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows remote authenticated administrators to upload dangerous file types via a ZIP archive in the e-paper draft upload function of SUNNET Corporate Training Management System v10.3. The flaw enables execution of arbitrary commands on the server by bypassing file type restrictions.

Detection Guidance

Detecting this vulnerability requires checking for unrestricted file uploads in the SUNNET Corporate Training Management System v10.3. Inspect the e-paper draft upload function for improper file type restrictions. Review server logs for unusual ZIP archive uploads containing executable files. Verify if uploaded files are stored in web-accessible directories.

Impact Analysis

An attacker with admin access could upload malicious files to take control of the server, steal data, or disrupt operations. This could lead to unauthorized access, data breaches, or system compromise affecting users and sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Immediately restrict file uploads to administrators only. Implement strict file type validation to block executable files in ZIP archives. Disable the e-paper draft upload function if not essential. Update to a patched version if available. Monitor for unauthorized command execution attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-24727. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart