PT-2026-20494 · Unknown · Mingsoft Mcms

Unnlucky1

·

Published

2026-02-18

·

Updated

2026-02-19

·

CVE-2026-2666

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mingSoft MCMS version 6.1.1
Description A flaw exists in mingSoft MCMS 6.1.1 related to unrestricted file upload. The issue is located within the Template Archive Handler component, specifically in a function associated with the /ms/file/uploadTemplate.do file. Manipulation of the File argument allows for unrestricted file uploads, and the attack can be initiated remotely. The exploit has been published.
Recommendations Apply any available updates or patches for mingSoft MCMS version 6.1.1. As a temporary workaround, restrict access to the /ms/file/uploadTemplate.do endpoint.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-2666
GHSA-R9WP-QQ53-QVJX

Affected Products

Mingsoft Mcms