SYS::ONLINE
Wasteland.
Briefs1674
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-7852 2026-06-11

CVE-2026-7852: Critical Unrestricted File Upload Flaw in Limatek LimRAD NAC

"A critical (CVSS 9.8) unrestricted file upload vulnerability in Limatek System Inc.'s LimRAD NAC allows unauthenticated remote attackers to achieve remote code inclusion on affected systems."

A critical (CVSS 9.8) unrestricted file upload vulnerability in Limatek System Inc.'s LimRAD NAC allows unauthenticated remote attackers to achieve remote code inclusion on affected systems.

What Is It

CVE-2026-7852 is an unrestricted upload of a file with a dangerous type (CWE-434) in Limatek System Inc.'s LimRAD NAC product. The flaw allows Remote Code Inclusion, meaning an attacker can upload a file of a dangerous type and have it processed or executed by the target system. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Why It Matters

The vulnerability is exploitable over the network with low attack complexity, requires no privileges, and needs no user interaction. A successful attack delivers high impact across confidentiality, integrity, and availability. Because LimRAD NAC is a network access control product, compromise could give an attacker a foothold at a sensitive control point in the network. The CVE was reported by Turkey's national CSIRT (USOM), and was published on June 11, 2026.

What's Vulnerable

The affected product is Limatek System Inc. LimRAD NAC. All versions before 5.5.7.3.9 are impacted. The supplied NVD record lists no specific affected CPEs beyond this version range.

Patch Status

The fix is present in LimRAD NAC version 5.5.7.3.9. Organizations running any earlier version should upgrade to 5.5.7.3.9 or later. The supplied source material contains no CISA KEV entry for this CVE, so there is no confirmation of active exploitation in the provided data, and no KEV-mandated remediation deadline.

Sources