Impact
Enterprise Cloud Database developed by Ragic has an arbitrary file upload flaw that allows attackers to upload any file without authentication and subsequently make it available for download. The vulnerability, classified as CWE‑434, permits the upload of malicious files that may be executed or processed later by the application or end users, potentially enabling code execution or other harmful actions.
Affected Systems
The affected product is Ragic: Enterprise Cloud Database. On‑premises installations must be updated to the patched release dated on or after April 10 2026; the cloud‑hosted version requires no remediation.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score of < 1% shows a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, although it can be exploited by any network user without authentication, making it readily exploitable. Attackers can target the upload endpoint directly over the network and deliver arbitrary files that may be processed or executed by the application or end users.
OpenCVE Enrichment