logo

CVE-2026-11839: Unrestricted File Upload Enables Web Shell Deployment in Rotaban

ID: aa47dd06-c308-5274-8acc-d1df51aac70e

STIX ID: report--aa47dd06-c308-5274-8acc-d1df51aac70e

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-12

Date Updated: 2026-06-13

...
...

A critical unrestricted file upload vulnerability (CVE-2026-11839, CVSS 9.9) in Rotaban allows authenticated low-privilege users to upload web shells (e.g., .php, .asp) and achieve remote code execution on the underlying host; a patch is available in Rotaban V2026.06.003 and the report includes mitigation and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.