Airleader Master versions 6.381 and prior allow for file uploads without
restriction to multiple webpages running maximum privileges. This could
allow an unauthenticated user to potentially obtain remote code
execution on the server.

Project Subscriptions

Vendors Products
Airleader Subscribe
Airleader Master Subscribe
Advisories

No advisories yet.

Fixes

Solution

Airleader recommends that users upgrade Airleader Master to version 6.386 or later. Users of Airleader Master are encouraged to reach out to Airleader via email (info@airleader.us) or submit a web form ( https://airleader.us/contact/ ) for more information and mitigation assistance.


Workaround

No workaround given by the vendor.

History

Tue, 17 Feb 2026 18:30:00 +0000

Type Values Removed Values Added
References

Fri, 13 Feb 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Airleader
Airleader airleader Master
Vendors & Products Airleader
Airleader airleader Master

Fri, 13 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 12 Feb 2026 21:45:00 +0000

Type Values Removed Values Added
Description Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.
Title Airleader Master Unrestricted Upload of File with Dangerous Type
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-02-17T18:03:38.837Z

Reserved: 2026-01-22T20:21:20.996Z

Link: CVE-2026-1358

cve-icon Vulnrichment

Updated: 2026-02-13T16:27:27.200Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-12T22:16:04.213

Modified: 2026-02-17T19:21:56.343

Link: CVE-2026-1358

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-13T21:29:20Z

Weaknesses