Description
File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.
Published: 2026-08-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

File upload vulnerability in T-Systems International GmbH ImageMaster Version 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function. The flaw enables execution of code with the privileges of the application, potentially giving full control over the system. The weakness is a classic example of untrusted file processing, which can compromise confidentiality, integrity, and availability of the affected environment.

Affected Systems

The affected product is T-Systems International GmbH ImageMaster, specifically version 9.14.2.8.1. No other versions or vendors are listed.

Risk and Exploitability

The CVSS base score is 8.8, indicating a high risk. The EPSS score of 0.00587 (less than 1%) indicates a low overall exploitation probability, yet the high CVSS score and the remote nature of the attack mean that exploitation remains a serious threat. The vulnerability is not listed in CISA KEV. The attack vector is presumed to be a web‑based file upload via the application’s interface, given that the vulnerability is triggered by the add attachments feature. If an attacker can reach this file upload endpoint, they can deliver a malicious payload and launch arbitrary code execution.

Generated by OpenCVE AI on August 28, 2026 at 20:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for ImageMaster if one is available
  • Configure the application to allow only approved file types and MIME types for attachments
  • Enforce strict file limits and quarantine uploaded files for analysis

Generated by OpenCVE AI on August 28, 2026 at 20:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via File Upload in T-Systems ImageMaster 9.14.2.8.1

Fri, 28 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title File upload vulnerability allows arbitrary code execution in T-Systems ImageMaster via attachment upload

Mon, 17 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title File upload vulnerability allows arbitrary code execution in T-Systems ImageMaster via attachment upload
Weaknesses CWE-434

Mon, 17 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-28T13:22:50.868Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50768

cve-icon Vulnrichment

Updated: 2026-08-17T19:57:35.567Z

cve-icon NVD

Status : Received

Published: 2026-08-17T18:17:08.760

Modified: 2026-08-28T16:18:13.860

Link: CVE-2026-50768

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:00:04Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type