CVE-2026-1358

EUVD-2026-6159
Airleader Master versions 6.381 and prior allow for file uploads without
 restriction to multiple webpages running maximum privileges. This could
 allow an unauthenticated user to potentially obtain remote code 
execution on the server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
icscertCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H