Home

Description

Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003.

PUBLISHED Reserved 2026-06-10 | Published 2026-06-11 | Updated 2026-06-17 | Assigner TR-CERT




CRITICAL: 9.9CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-434 Unrestricted upload of file with dangerous type

Product status

Default status
unaffected

V2026.06.002 (custom) before V2026.06.003
affected

Credits

Mehmet MURAT finder

Ömer Faruk KAYIKCI finder

References

siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0367 government-resource

cve.org (CVE-2026-11839)

nvd.nist.gov (CVE-2026-11839)

Download JSON