← Vulnerability feed

Vulnerability record · CVE-2026-7490 · published 2 May 2026

CVE-2026-7490: Sun.net ehrd cpas unrestricted file upload vulnerability

SSun.Net · Ehrd Cpas

CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

8.6 CVSS 4.0 High EPSS 0.83% · top 44.2% CWE-434 · Unrestricted file upload
8.6CVSS 4.0 base score
0.83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-7490 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-54945Sun.net ehrd ctms vulnerabilityAn external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute…EPSS 0.54%9.8CVE-2024-10440Sun.net ehrd ctms sql injection vulnerabilityThe eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modif…EPSS 0.55%9.3CVE-2025-54946Sun.net ehrd ctms sql injection vulnerabilityA SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands.EPSS 0.48%9.3CVE-2025-54943Sun.net ehrd ctms missing authorization vulnerabilityA missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized app…EPSS 0.50%9.3CVE-2025-54942Sun.net ehrd ctms missing authentication for critical function vulnerabilityA missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to a…EPSS 0.48%8.8CVE-2023-24836Sun.net ehrd ctms path traversal vulnerabilitySUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can …EPSS 1.2%8.7CVE-2026-7489Sun.net ehrd ctms sql injection vulnerabilityCTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify,…EPSS 0.55%7.5CVE-2024-10438Sun.net ehrd ctms authentication bypass via alternate path vulnerabilityThe eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfyin…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2026-7490), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.