Description
Unrestricted upload of file with dangerous type vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd. Eimzamip allows Using Malicious Files.

This issue affects eimzamip: from v1.6.4 before v1.6.6.
Published: 2026-10-08
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

The vulnerability in İzometri IT Services eimzamip allows an attacker to upload files of dangerous types without restriction. This flaw can enable the execution of arbitrary code on the web server or the application, compromising confidentiality, integrity, and availability of the affected system. The weakness is a classic unchecked file upload flaw, classified under CWE-434.

Affected Systems

İzometri IT Services Domestic and Foreign Trade Co. Ltd. provides the eimzamip product. Versions affected are those from v1.6.4 up to but not including v1.6.6, i.e., any release prior to and including v1.6.5.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity. The EPSS score is not available, so current exploitation likelihood cannot be quantified, but the issue is not listed in CISA KEV, implying no confirmed exploit yet. The likely attack vector is remote, via the web application’s file upload endpoint; an attacker with access to that interface can upload a malicious file and trigger code execution. The flaw requires that the victim’s environment accepts the file and that the uploaded payload has an execution context, such as a web application with sufficient privileges.

Generated by OpenCVE AI on October 8, 2026 at 16:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade eimzamip to v1.6.6 or newer to remove the upload flaw
  • If a patch is unavailable, restrict the upload endpoint to allow only safe file types and reject all others
  • Implement server‑side validation and scanning of uploaded files to block executable or dangerous content

Generated by OpenCVE AI on October 8, 2026 at 16:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unrestricted upload of file with dangerous type vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd. Eimzamip allows Using Malicious Files. This issue affects eimzamip: from v1.6.4 before v1.6.6.
Title Remote Code Execution via Unrestricted File Upload in İzometri Informatics' eimzamip
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-10-08T13:57:24.257Z

Reserved: 2026-09-15T08:35:49.507Z

Link: CVE-2026-91844

cve-icon Vulnrichment

Updated: 2026-10-08T13:57:19.839Z

cve-icon NVD

Status : Received

Published: 2026-10-08T14:17:02.167

Modified: 2026-10-08T14:17:02.167

Link: CVE-2026-91844

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:00:18Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type