CVE-2026-67243

HIGH

Refirio freo2 < Ver 2.0.0-alpha-14 - Unrestricted Upload of File with Dangerous Type

Title source: rule
STIX 2.1

Description

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.

Scores

CVSS v3 7.2
EPSS 0.0030
EPSS Percentile 22.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
refirio/freo2 < Ver 2.0.0-alpha-14
Published Aug 04, 2026
Tracked Since Aug 04, 2026