GHSA-98gc-mw7m-prrh
An arbitrary file upload vulnerability exists in TemplateSpare versions up to and including 4.2.0, exploitable by an administrator. This vulnerability allows an attacker with administrative privileges to upload files without proper validation, potentially leading to complete system compromise. The vulnerability is classified as critical due to its high impact on confidentiality, integrity, and availability.
AI Analysis
Technical Summary
CVE-2026-57658 is an administrator-level arbitrary file upload vulnerability affecting TemplateSpare versions <= 4.2.0. It is identified as CWE-434 (Unrestricted Upload of File with Dangerous Type). The vulnerability allows an attacker with administrative privileges to upload arbitrary files, which can lead to full system compromise including confidentiality, integrity, and availability impacts. The CVSS 3.1 vector indicates network attack vector, low attack complexity, high privileges required, no user interaction, scope changed, and high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows an attacker with administrative privileges to upload arbitrary files, potentially leading to complete compromise of the affected system's confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, administrators should monitor vendor communications for updates and consider restricting administrator file upload capabilities or applying compensating controls until a fix is available.
GHSA-98gc-mw7m-prrh
Description
An arbitrary file upload vulnerability exists in TemplateSpare versions up to and including 4.2.0, exploitable by an administrator. This vulnerability allows an attacker with administrative privileges to upload files without proper validation, potentially leading to complete system compromise. The vulnerability is classified as critical due to its high impact on confidentiality, integrity, and availability.
CVSS v3.1
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-57658 is an administrator-level arbitrary file upload vulnerability affecting TemplateSpare versions <= 4.2.0. It is identified as CWE-434 (Unrestricted Upload of File with Dangerous Type). The vulnerability allows an attacker with administrative privileges to upload arbitrary files, which can lead to full system compromise including confidentiality, integrity, and availability impacts. The CVSS 3.1 vector indicates network attack vector, low attack complexity, high privileges required, no user interaction, scope changed, and high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows an attacker with administrative privileges to upload arbitrary files, potentially leading to complete compromise of the affected system's confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, administrators should monitor vendor communications for updates and consider restricting administrator file upload capabilities or applying compensating controls until a fix is available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-98gc-mw7m-prrh
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-57658"]
- Ecosystems
- []
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6a3ef79927e9c79719ffab0c
Added to database: 06/26/2026, 22:05:13 UTC
Last enriched: 06/26/2026, 22:20:45 UTC
Last updated: 06/27/2026, 00:51:23 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.