CVE-2026-6885 PUBLISHED

BorG Technology Corporation|Borg SPM 2007 - Arbitrary File Upload

Assigner: twcert
Reserved: 23.04.2026 Published: 23.04.2026 Updated: 23.04.2026

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor BorG Technology Corporation
Product Borg SPM 2007
Versions Default: unaffected
  • Version 0 is affected

Solutions

Regardless of the current system version, customers with active maintenance contracts are advised to contact the vendor for patching assistance or upgrade to the latest version (SPM2025 SP1 has successfully passed source code security audits).

References

Problem Types

  • CWE-434 Unrestricted upload of file with dangerous type CWE

Impacts

  • CAPEC-650 Upload a Web Shell to a Web Server