A CVSS 9.8 unrestricted file upload vulnerability in TRtek's Software Repository Management product allows unauthenticated remote attackers to plant a web shell on the server.
What Is It
CVE-2026-16286 is an unrestricted upload of file with dangerous type flaw (CWE-434) in Software Repository Management, developed by TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company. The vulnerability permits an attacker to upload a web shell to the web server, which would typically yield arbitrary code execution in the application's context.
The CVSS 3.1 vector, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, describes the worst-case profile: network-reachable, low complexity, no privileges, and no user interaction, with total loss of confidentiality, integrity, and availability. Base score is 9.8 (CRITICAL). The record was published 2026-08-25 by USOM (Turkey's national CERT) and currently carries NVD status "Received."
Why It Matters
Web shell upload on an unauthenticated, network-facing endpoint is about as direct as initial access gets. There is no gating condition to satisfy; no valid session, no phishing step, no local foothold. In most deployments, an attacker who can reach the application should be assumed to have a path to the file system.
CISA's SSVC assessment scores this as exploitation: none, automatable: yes, technicalImpact: total. No confirmed in-the-wild exploitation is recorded at this time, and the CVE does not appear in the CISA Known Exploited Vulnerabilities catalog. The "automatable: yes" determination is the notable part: reconnaissance, weaponization, and delivery can all be scripted, which is the profile that historically precedes mass opportunistic scanning.
What's Vulnerable
- Vendor: TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company
- Product: Software Repository Management
- Affected versions: all versions prior to commit
2fb4acee
Versioning here is by commit hash rather than a semantic release number, so operators should confirm their deployed build against the vendor's repository. No CPE entries have been assigned in the NVD record.
Patch Status
A fix exists. Software Repository Management builds at or after commit 2fb4acee are unaffected; everything before that is vulnerable. No specific remediation deadline or required action has been mandated, as the CVE is not KEV-listed. Operators running affected builds should update to a post-2fb4acee version and, given the web shell impact, audit upload directories and web-accessible paths for unexpected files.
Sources
- NVD, CVE-2026-16286: https://nvd.nist.gov/vuln/detail/CVE-2026-16286
- USOM (Turkish National Cyber Incident Response Center) Advisory TR-26-0899: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0899