CVE-2026-4999Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in z-9527 admin up to 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2. This issue affects the function uploadFile of the file /server/utils/upload.js of the component isImg Check. The manipulation of the argument fileType leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-29)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-28: 1Mentions · 2026-03-29: 2Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 103-2803-29
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-281
Disclosure1
2026-03-292
Disclosure1General1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4999 A security vulnerability has been detected in z-9527 admin up to 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2. This issue affects the function uploadFile of the file /serve… https://www.cve.org/CVERecord?id=CVE-2026-4999

    Post summary

    A new vulnerability, CVE-2026-4999, has been identified in the z-9527 admin system, affecting the uploadFile function; no PoC, exploit tools, active exploitation, patches, or workaround details are provided.

    0001083
    56.9K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4999 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4999 #CVE-2026-4999 #CVE #Medium #CyberSecurity #InfoSec https://t.co/rmV63afzsm

    Post summary

    The tweet announces CVE-2026-4999 with a medium severity rating and links to the NVD entry, but provides no technical, exploit, or patch details.

    0000027
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4999 - z-9527 admin isImg Check upload.js uploadFile path traversal Intel Report: https://ift.tt/LClXzj1

    Post summary

    The notice highlights a newly identified path traversal flaw (CVE-2026-4999) in the z-9527 admin isImg Check upload.js uploadFile component, offering only brief technical details and pointing to an Intel report.

    0000018
    283 followersView on X

Explore more