CVE-2026-16286 PUBLISHED

File Upload in TRTEK Software's Software Repository Management

Assigner: TR-CERT
Reserved: 20.07.2026 Published: 25.08.2026 Updated: 25.08.2026

Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server.

This issue affects Software Repository Management: before 2fb4acee.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company
Product Software Repository Management
Versions Default: unaffected
  • affected from 0 to 2fb4acee (excl.)

Credits

  • Muhammet Talha ODABASI finder
  • Yunus KARA finder
  • Abdurrahman Emre OZKOK coordinator

References

Problem Types

  • CWE-434 Unrestricted upload of file with dangerous type CWE

Impacts

  • CAPEC-650 Upload a Web Shell to a Web Server