CVE-2026-42099Disclosure(sparxsystems / pro_cloud_server)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch sparxsystems pro_cloud_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties of the object pointed by guid parameter and saves loaded content in current location (__DIR__) under the specified name. An attacker with repository access can control both the filename and file contents, allowing the creation of a malicious PHP file in a current directory. Although the file is deleted after processing, a race condition exists: if the response transmission is delayed (e.g., via a large file or slow client connection), the file remains accessible. During this window, the attacker can issue a second request to execute the malicious PHP file, resulting in remote code execution. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pro_cloud_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-19); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
pro_cloud_server

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-19: 1Mentions · 2026-05-21: 1Mentions · 2026-06-02: 1PoC Mentioned / Linked · 2026-05-21: 1Active Exploitation · 2026-05-21: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-21: 1Technical Details · 2026-06-02: 105-1905-2106-02
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-191
Disclosure1
2026-05-211
Active Exploitation1
2026-06-021
Disclosure1
Full discourse3 posts
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: 1 critical, 4 High, all actively exploited vulnerabilities in #Sparx Pro Cloud Server, Enterprise Architect #CVE-2026-42096 #CVE-2026-42097 #CVE-2026-42098 #CVE-2026-42099 #CVE-2026-42100 CVSS: 9.3-7.1 #PoC available #Patch #Patch #Patch

    Post summary

    This post warns that five CVEs in Sparx Pro Cloud Server are actively exploited, provides PoC references, and cites available patches, underscoring the urgency of remediation.

    01010224
    7.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Sparx Pro Cloud Server, Race Condition RCE, #CVE-2026-42099 (Critical) -DC-Jun2026-117 https://dailycve.com/sparx-pro-cloud-server-race-condition-rce-cve-2026-42099-critical-dc-jun2026-117/

    Post summary

    The post announces a new critical race‑condition RCE vulnerability (CVE‑2026‑42099) affecting Sparx Pro Cloud Server but provides no proof‑of‑concept, exploit code, or patch information.

    0000036
    209 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42099 Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties of the object po… https://www.cve.org/CVERecord?id=CVE-2026-42099

    Post summary

    Sparx Pro Cloud Server has a race condition vulnerability in a specific endpoint; no exploit, patch, or active exploitation reported.

    00000141
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsparxsystemspro_cloud_server---

Explore more