CVE-2026-80233

Summary

CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shells backdoors, thereby enabling arbitrary code execution on the server.

Affected Software

VendorProductVersion RangeStatus
CAYIN TechnologyCAYIN CMS-WS0 <= 1.0.25336affected
CAYIN TechnologyCAYIN CMS-SE0 <= 11.0.25336affected
CAYIN TechnologyCAYIN SMP0 <= 4.0.25336affected

Weaknesses

  • CWE-434: CWE-434 Unrestricted Upload of File with Dangerous Type

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References