Executive brief
The Gotac Police Statistics Database System contains a critical security flaw that allows unauthorized individuals to upload malicious files to the server. This system is used for managing sensitive law enforcement data, and an exploit could allow an attacker to take full control of the server, potentially leading to data theft, service disruption, or unauthorized access to police records. Although this specific CVE identifier was later rejected by the numbering authority, the underlying technical issue was reported to affect versions up to 1.0.2.
Technical details
The Gotac Police Statistics Database System (versions <= 1.0.2) is vulnerable to an arbitrary file upload (CWE-434). An unauthenticated remote attacker can exploit this by uploading a malicious file, such as a web shell, to the server. Because the application fails to properly validate the type or content of uploaded files, the attacker can subsequently execute these files to achieve full remote code execution (RCE) with the privileges of the web service. While the CVE-2026-1021 ID was marked as 'Rejected' by TWCERT/CC, the initial disclosure detailed a critical impact with a CVSS 3.1 score of 9.8.
Affected products
- Gotac Police Statistics Database System up to and including 1.0.2
Timeline
- 2026-01-15: disclosed: Initial disclosure by TWCERT/CC
- 2026-01-16: advisory: NVD published the CVE entry
- 2026-07-30: other: CVE ID was rejected/withdrawn by the CNA