CVE-2026-22789CWE-434CWE-616

WebErpMesv2 has a File Upload Validation Bypass Leading to RCE

Medium · published January 12, 2026

CVSS v3.1
5.4
EPSS
0%
Percentile
15.5
In the wild
Unconfirmed
What it is

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, WebErpMesv2 contains a file upload validation bypass vulnerability in multiple controllers that allows authenticated users to upload arbitrary files, including PHP scripts, leading to Remote Code Execution (RCE). This vulnerability is identical in nature to CVE-2025-52130 but exists in different code locations that were not addressed by the original fix. This vulnerability is fixed in 1.19.

The record
Technical detail
CVSS v3.1
5.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00244 · 15.5th percentile
Weaknesses
CWE-434 · Unrestricted Upload of File with Dangerous Type; CWE-616 · Incomplete Identification of Uploaded File Variables (PHP)
Published
2026-01-12T21:52Z
EPSS history
Timeline
  • 12 JAN 21:52Z
    WebErpMesv2 has a File Upload Validation Bypass Leading to RCE
    cvelistv5