PT-2026-26278 · Unknown · Syarif Mobile App Editor

·

CVE-2026-27067

·

Published

2026-03-19

·

Updated

2026-03-23

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Syarif Mobile App Editor versions n/a through 1.3.1
Description The software is susceptible to an unrestricted file upload issue that permits the uploading of a web shell to a web server. This allows attackers to potentially achieve remote code execution. The issue stems from a lack of validation during the file upload process.
Recommendations Versions prior to 1.3.1 should be updated.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27067

Affected Products

Syarif Mobile App Editor