Description
Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload malicious files and make them available for users to download.
Published: 2026-07-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Enterprise Cloud Database developed by Ragic has an arbitrary file upload flaw that allows attackers to upload any file without authentication and subsequently make it available for download. The vulnerability, classified as CWE‑434, permits the upload of malicious files that may be executed or processed later by the application or end users, potentially enabling code execution or other harmful actions.

Affected Systems

The affected product is Ragic: Enterprise Cloud Database. On‑premises installations must be updated to the patched release dated on or after April 10 2026; the cloud‑hosted version requires no remediation.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the EPSS score of < 1% shows a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, although it can be exploited by any network user without authentication, making it readily exploitable. Attackers can target the upload endpoint directly over the network and deliver arbitrary files that may be processed or executed by the application or end users.

Generated by OpenCVE AI on August 1, 2026 at 10:56 UTC.

Remediation

Vendor Solution

No action is required for the cloud version; the on-premises version must be updated to the patch released on or after April 10, 2026.


OpenCVE Recommended Actions

  • Update the on‑premises Ragic Enterprise Cloud Database to the patched release dated on or after April 10 2026.
  • If patching is not immediately possible, configure the application to reject all file uploads whose type or extension is not explicitly permitted, or block the upload endpoint entirely to prevent unauthenticated uploads.
  • Monitor upload and download logs for unexpected or malicious activity and enforce strict access controls on any files that have been uploaded.

Generated by OpenCVE AI on August 1, 2026 at 10:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Ragic
Ragic enterprise Cloud Database
Vendors & Products Ragic
Ragic enterprise Cloud Database

Mon, 13 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Description Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload malicious files and make them available for users to download.
Title Ragic|Enterprise Cloud Database - Arbitrary File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ragic Enterprise Cloud Database
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-07-14T14:33:25.148Z

Reserved: 2026-07-13T01:32:22.505Z

Link: CVE-2026-15553

cve-icon Vulnrichment

Updated: 2026-07-14T14:12:34.432Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:00:04Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type