Description
The application uses unsafe functions that allow execution of inline scripts and string evaluation functions.
Published: 2026-09-29
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted code execution via unsafe eval functions
Action: Immediate patch
AI Analysis

Impact

The vulnerability arises from the use of unsafe functions that allow execution of inline scripts and string evaluation. This lack of input sanitization enables arbitrary code to run within the application, potentially providing an attacker with the ability to execute malicious scripts. The weakness aligns with CWE-95 and could compromise the confidentiality, integrity and availability of the system if exploited.

Affected Systems

Affected systems include Toptech Systems' TMS7 and TopHAT products. Versions prior to 7.8 are vulnerable; the issue was addressed in the 7.8 release. Administrators should verify the current version of these applications and plan an upgrade.

Risk and Exploitability

The CVSS score of 2.1 indicates low overall severity. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, suggesting limited known exploitation. However, the lack of input validation and use of eval functions present a theoretical attack path, especially if an attacker can supply trusted input or manipulate configuration files. Based on the description, it is inferred that the attack vector may involve a trusted user or an administrator who can supply data that is processed by the unsafe functions.

Generated by OpenCVE AI on September 30, 2026 at 10:19 UTC.

Remediation

Vendor Solution

Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security


OpenCVE Recommended Actions

  • Upgrade TMS7 and TopHAT to version 7.8 or newer
  • Follow the vendor's security advisory for any post‑upgrade configuration changes
  • As a temporary measure, restrict or remove the use of inline scripts and string eval functions in the application configuration, ensuring proper input validation

Generated by OpenCVE AI on September 30, 2026 at 10:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description The application uses unsafe functions that allow execution of inline scripts and string evaluation functions.
Title Toptech TMS7 and TopHAT Eval Injection
Weaknesses CWE-95
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-30T15:28:14.420Z

Reserved: 2026-08-10T17:31:09.958Z

Link: CVE-2026-69662

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T22:17:58.803

Modified: 2026-09-30T16:46:43.953

Link: CVE-2026-69662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T10:30:17Z

Weaknesses
  • CWE-95

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')