CVE-2026-88738
8.8 HIGHPublished 2026-09-21 · Updated 2026-09-22
AI risk analysis
- Summary
- The Jazzware RT1000 Edge webUI v. 20.0.1 allows an attacker with administrative privileges to upload a server-side executable file, leading to remote code execution.
- Exploitability
- Exploitation requires administrative privileges and access to the upgrade package upload functionality. The vulnerability is relatively straightforward to exploit once the attacker gains the necessary access.
- Blast radius
- If exploited, the vulnerability could result in complete control over the affected system, including data exfiltration, further exploitation, and disruption of services.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable the upgrade package upload functionality or restrict access to this feature to users with administrative privileges.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
All references
- https://lcybersec.notion.site/CVE-2026-88738-Unrestricted-file-upload-vulnerability-resulting-in-remote-code-execution-in-Jazzwa-3e06e8f484b5809e9eb3ffa705995d22
- https://lcybersec.notion.site/CVE-2026-88738-Unrestricted-file-upload-vulnerability-resulting-in-remote-code-execution-in-Jazzwa-3e06e8f484b5809e9eb3ffa705995d22
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-12264
- CRITICALCVE-2026-14175
- CRITICALCVE-2026-18143
- HIGHCVE-2026-54416PoC
- HIGHCVE-2026-6147
- CRITICALCVE-2026-70356PoC
- CRITICALCVE-2026-82187
- CRITICALCVE-2026-82901
Related by shared AI tags and CWE weakness class. Browse the full archive.