CVE-2026-7490

7.2

Sunnet · CTMS and CPAS

Sunnet CTMS and CPAS contain an arbitrary file upload vulnerability that allows privileged remote attackers to execute web shell backdoors.

Executive summary

An arbitrary file upload vulnerability in Sunnet CTMS and CPAS allows privileged remote attackers to achieve remote code execution on the underlying server.

Vulnerability

This flaw stems from an unrestricted upload of files with dangerous types, categorized under CWE-434, which permits authenticated, highly privileged remote attackers to upload and execute malicious web shells.

Business impact

A successful exploitation of this vulnerability can lead to complete system compromise, giving attackers unauthorized control over the affected server. Given the CVSS score of 7.2, the high severity rating reflects the potential for total loss of confidentiality, integrity, and availability of the hosting environment, which could disrupt business operations and expose sensitive organizational data.

Remediation

Immediate Action: Apply vendor security updates immediately as soon as they become available from Sunnet, or contact the vendor directly for guidance.

Proactive Monitoring: Monitor server access logs and file system integrity for the unexpected creation of executable scripts or anomalous web requests targeting upload endpoints.

Compensating Controls: Implement strict web server directory permissions and deploy Web Application Firewalls to inspect and block malicious file uploads.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Organizations utilizing Sunnet CTMS and CPAS must treat this vulnerability with high urgency despite the requirement for administrative access. Administrators should audit administrative account security, restrict network access to management interfaces, and apply vendor patches immediately upon release.

More Sunnet CVEs

Sources