HIGH

CVE-2026-67243

2026-08-04 CVSS v3.0
CVSS
7.2

Description

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.

Weakness (CWE)

CWE-434 Unrestricted File Upload

EPSS Score

0.32%
Probability of exploitation in next 30 days
25th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE