← back
CVE-2026-1358criticalCWE-434

Airleader Master Unrestricted Upload of File with Dangerous Type

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.3epss 1.2%
exploitation probability
1.2%top 33% of all CVEs
observed exploitation
nono source reports it
Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N