CVE-2026-67243

Summary

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.

Affected Software

VendorProductVersion RangeStatus
refiriofreo20 < Ver 2.0.0-alpha-14affected

Weaknesses

  • CWE-434: Unrestricted upload of file with dangerous type

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References