CVE-2026-102263
Received Received - Intake

Unrestricted File Upload in Robo-Café RMS

Vulnerability report for CVE-2026-102263, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulDB

Description

A vulnerability has been found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The affected element is an unknown function of the file manage-food.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mwasikz robo-cafe-rms to 228c44a02823f04e85db32b7137809a2856148fc (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unrestricted file upload issue in the mwasikz robo-cafe-rms software, specifically in the manage-food.php file. An attacker can remotely exploit this to upload malicious files without restrictions due to improper input validation.

Detection Guidance

This vulnerability involves unrestricted file uploads via manage-food.php in mwasikz robo-cafe-rms. To detect it, inspect the file upload functionality in manage-food.php for improper file type validation. Check server logs for unexpected file uploads or suspicious file extensions. Monitor for unauthorized file execution in web-accessible directories.

Impact Analysis

The impact includes potential remote code execution, malware distribution, or unauthorized access to the system. Attackers could leverage this to compromise the robo-cafe-rms server or deliver malicious payloads to users interacting with the system.

Compliance Impact

This vulnerability allows unrestricted file uploads due to improper input validation in manage-food.php. This could lead to unauthorized access or execution of malicious files, potentially violating data protection requirements under GDPR and HIPAA by exposing sensitive information or enabling data breaches.

Mitigation Strategies

Immediately restrict access to the manage-food.php file and review all uploaded files for malicious content. Disable remote upload functionality if not required. Monitor network traffic for unusual activity related to file uploads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102263. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart