CVE-2026-88738
Medium
Elevated severity or exploit probability.
CVSS base
8.8
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.9%
56.7th percentile
CISA KEV
Not listed
Weakness / dates
CWE-434
Published 2026-09-21 · modified 2026-09-22
Description
Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.
References
- https://lcybersec.notion.site/CVE-2026-88738-Unrestricted-file-upload-vulnerability-resulting-in-remote-code-execution-in-Jazzwa-3e06e8f484b5809e9eb3ffa705995d22
- https://lcybersec.notion.site/CVE-2026-88738-Unrestricted-file-upload-vulnerability-resulting-in-remote-code-execution-in-Jazzwa-3e06e8f484b5809e9eb3ffa705995d22