SYS::ONLINE
Wasteland.
Briefs1674
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-11839 2026-06-11

CVE-2026-11839: Critical Web Shell Upload Flaw in Başarsoft Rotaban

"A critical unrestricted file upload vulnerability in Başarsoft Rotaban allows attackers to upload a web shell to the server, earning a CVSS score of 9.9."

A critical unrestricted file upload vulnerability in Başarsoft Rotaban allows attackers to upload a web shell to the server, earning a CVSS score of 9.9.

What Is It

CVE-2026-11839 is an unrestricted upload of file with dangerous type vulnerability (CWE-434) in Başarsoft Information Technologies Inc. Rotaban. The flaw allows an attacker to upload a web shell to a web server, providing a foothold for remote code execution and further compromise. It was published on 2026-06-11 by USOM (the Turkish national CERT, [email protected]) and currently carries a vulnerability status of "Deferred."

Why It Matters

The vulnerability is rated CRITICAL with a CVSS 3.1 base score of 9.9 (vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). It is exploitable over the network with low attack complexity and requires only low privileges, with no user interaction. The scope is "Changed," and confidentiality, integrity, and availability impacts are all rated HIGH. A successful web shell upload typically grants an attacker persistent, server-side control; enabling data theft, defacement, and pivoting deeper into the affected environment.

The supplied source material contains no CISA KEV entry for this CVE, so there is no confirmation of active exploitation at this time.

What's Vulnerable

The affected product is Başarsoft Rotaban. According to the NVD record, the issue affects Rotaban from version V2026.06.002 before V2026.06.003. No specific affected CPEs were enumerated in the supplied data.

Patch Status

The version range indicates the fix lands in V2026.06.003; versions from V2026.06.002 up to (but not including) V2026.06.003 are vulnerable. Organizations running Rotaban V2026.06.002 should upgrade to V2026.06.003 to remediate. Consult the USOM advisory for vendor-specific guidance. No additional CISA-mandated required action is present in the supplied source material.

Sources