← Terug naar overzicht

CVE-2026-16286 describes an unrestricted file upload vulnerability in TRtek Technological Products' Software Repository Management application. The flaw allows attackers to upload files with dangerous types, enabling the deployment of a web shell to the affected web server. Successful exploitation grants an attacker remote code execution capabilities on the server. All versions of Software Repository Management prior to commit 2fb4acee are affected. The vulnerability is classified under CWE for unrestricted upload of files with dangerous types. The advisory was published by the Turkish cybersecurity authority (siberguvenlik.gov.tr). No workarounds are noted; patching to the fixed commit is the recommended remediation. The issue carries a high criticality rating due to the direct risk of server compromise.

Affected products

  • TRtek Software Repository Management

Related CVE's

  • CVE-2026-16286

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities