← Back to search

CVE-2026-88738

8.8 HIGH

Published 2026-09-21 · Updated 2026-09-22

AI risk analysis

Summary
The Jazzware RT1000 Edge webUI v. 20.0.1 allows an attacker with administrative privileges to upload a server-side executable file, leading to remote code execution.
Exploitability
Exploitation requires administrative privileges and access to the upgrade package upload functionality. The vulnerability is relatively straightforward to exploit once the attacker gains the necessary access.
Blast radius
If exploited, the vulnerability could result in complete control over the affected system, including data exfiltration, further exploitation, and disruption of services.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the upgrade package upload functionality or restrict access to this feature to users with administrative privileges.
rcewebadmin-privupload

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.