CVE-2026-7490
7.2Sunnet · CTMS and CPAS
Sunnet CTMS and CPAS contain an arbitrary file upload vulnerability that allows privileged remote attackers to execute web shell backdoors.
Executive summary
An arbitrary file upload vulnerability in Sunnet CTMS and CPAS allows privileged remote attackers to achieve remote code execution on the underlying server.
Vulnerability
This flaw stems from an unrestricted upload of files with dangerous types, categorized under CWE-434, which permits authenticated, highly privileged remote attackers to upload and execute malicious web shells.
Business impact
A successful exploitation of this vulnerability can lead to complete system compromise, giving attackers unauthorized control over the affected server. Given the CVSS score of 7.2, the high severity rating reflects the potential for total loss of confidentiality, integrity, and availability of the hosting environment, which could disrupt business operations and expose sensitive organizational data.
Remediation
Immediate Action: Apply vendor security updates immediately as soon as they become available from Sunnet, or contact the vendor directly for guidance.
Proactive Monitoring: Monitor server access logs and file system integrity for the unexpected creation of executable scripts or anomalous web requests targeting upload endpoints.
Compensating Controls: Implement strict web server directory permissions and deploy Web Application Firewalls to inspect and block malicious file uploads.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Organizations utilizing Sunnet CTMS and CPAS must treat this vulnerability with high urgency despite the requirement for administrative access. Administrators should audit administrative account security, restrict network access to management interfaces, and apply vendor patches immediately upon release.