CVE-2026-67243
Received Received - Intake

Unrestricted File Upload in freo2 Allows OS Command Execution

Vulnerability report for CVE-2026-67243, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: JPCERT/CC

Description

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
refirio freo2 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in freo2 by refirio allows an administrator to upload executable files that can execute arbitrary operating system commands. This occurs due to unrestricted file upload functionality.

Impact Analysis

An attacker with highest-level admin access could upload malicious files to execute arbitrary commands on the system, potentially leading to full system compromise, data theft, or unauthorized system changes.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's integrity and confidentiality requirements and HIPAA's security rules for protected health information.

Mitigation Strategies

Restrict administrative privileges to prevent unauthorized file uploads. Disable or remove the ability to upload executable files in freo2. Monitor for suspicious file uploads or unusual command execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67243. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart