Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.
History

Thu, 12 Feb 2026 21:45:00 +0000

Type Values Removed Values Added
Description Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.
Title Airleader Master Unrestricted Upload of File with Dangerous Type
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-02-12T21:24:53.070Z

Reserved: 2026-01-22T20:21:20.996Z

Link: CVE-2026-1358

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-12T22:16:04.213

Modified: 2026-02-13T14:23:48.007

Link: CVE-2026-1358

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.