LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-42099

sparxsystems · pro cloud server

Published
CVSS7.5
Severityhigh
WeaknessCWE-362
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties of the object pointed by guid parameter and saves loaded content in current location (__DIR__) under the specified name. An attacker with repository access can control both the filename and file contents, allowing the creation of a malicious PHP file in a current directory. Although the file is deleted after processing, a race condition exists: if the response transmission is delayed (e.g., via a large file or slow client connection), the file remains accessible. During this window, the attacker can issue a second request to execute the malicio

References

← Back to the CVE Tracker

Our coverage of CVE-2026-42099

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-42099.