What is CVE-2026-24727?
An unrestricted upload of file with dangerous type vulnerability has been identified in the e-paper draft upload function of SUNNET Corporate Training Management System up to version 10.3. This flaw allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a specially crafted ZIP archive. Affected systems should restrict administrator access to the ZIP upload functionality.
Azərbaycanca: SUNNET Corporate Training Management System-in v10.3-ə qədər versiyalarında elektron kağız qaralama yükləmə funksiyasında təhlükəli fayl tipinin məhdudiyyətsiz yüklənməsi zəifliyi aşkarlanıb. Bu boşluq autentifikasiya olunmuş administratorlara xüsusi hazırlanmış ZIP arxivi vasitəsilə ixtiyari əmrlər icra etməyə imkan verir. Təsirə məruz qalan sistemlərdə administratorlar ZIP yükləmə funksiyasına girişi məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which versions of SUNNET Corporate Training Management System are affected by CVE-2026-24727?
This vulnerability affects SUNNET Corporate Training Management System up to version 10.3.
What privileges are required to exploit CVE-2026-24727?
Exploitation of this vulnerability requires remote authenticated administrator privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.