Junglewise Threat Intelligence

CVE-2025-10856: Solvera Teknoera unrestricted file upload

CVE-2025-10856 · Severity: high · CVSS 8.1 · Published 2026-01-22

Executive brief

Solvera Teknoera contains a security flaw that allows users to upload unauthorized and potentially malicious files to the system. This could allow an attacker to inject harmful content or execute unauthorized code, potentially leading to a full compromise of the application and its data. The vulnerability impacts versions of the software released through early 2025.

Technical details

An unrestricted upload of file with dangerous type (CWE-434) vulnerability exists in Solvera Software Services Trade Inc. Teknoera through version 01102025. The flaw allows an authenticated attacker with low privileges to upload files with dangerous extensions or content over the network. This can lead to file content injection and potentially remote code execution (RCE) on the underlying server. The vulnerability is assigned a CVSS score of 8.1, reflecting high impact on confidentiality and integrity.

Affected products

  • Solvera Software Services Trade Inc. Teknoera through 01102025

Timeline

  • 2026-01-22: disclosed
  • 2026-01-22: advisory

References

Related threats