What is CVE-2026-49827?
CVE-2026-49827 allows any self-registered user in WebErpMesv2 (versions 1.19 and prior) to upload arbitrary PHP files via the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration, this poses a critical takeover risk, requiring immediate patching and restriction of the registration process.
Azərbaycanca: CVE-2026-49827, WebErpMesv2 resurs idarəetmə sisteminin 1.19 və əvvəlki versiyalarında qeydiyyatdan keçmiş istənilən istifadəçiyə HR Expense scan_file parametri vasitəsilə PHP faylı yükləməyə imkan verir, bu isə uzaqdan kod icrasına (Remote Code Execution) səbəb olur. Açıq qeydiyyat funksiyası ilə birlikdə bu, sistemin tam ələ keçirilməsi riskini artırır. İstifadəçilər dərhal təhlükəsizlik yeniləməsini tətbiq etməli və qeydiyyat prosesini məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-434
FAQ1
How does CVE-2026-49827 affect the WebErpMesv2 system?
CVE-2026-49827 allows any self-registered user in WebErpMesv2 (versions 1.19 and prior) to upload arbitrary PHP files via the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration, this poses a critical takeover risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.