Impact
TarsWeb lacks proper authorization checks in key patch‑management endpoints: upload-and-apply, download, delete, and setting the default package. As a result, any authenticated user, even one with a role scoped to an unrelated application, can upload a patch, trigger its deployment on any server managed by the console, retrieve or delete other applications’ packages, and change which patch a given application deploys by default. This lack of access control allows attackers to execute arbitrary code on target servers, delete critical data, and disrupt application operation, constituting a severe privilege escalation flaw.
Affected Systems
This vulnerability affects all installations of TarsWeb up to and including version 3.0.16. The issue exists in the application’s PatchController module for TarsCloud’s TarsWeb product.
Risk and Exploitability
With a CVSS score of 8.7 the flaw is considered high severity. The EPSS score is unavailable, but the vulnerability is listed as not in the CISA KEV catalog. The attack likely proceeds from an authenticated user session on the web console; explicit attack vectors are not documented, but inference indicates that any authenticated user can exploit the missing authorizations. The propagation can affect all servers managed by the TarsWeb instance, making the risk landscape broad for deployments using this product.
OpenCVE Enrichment