Junglewise Threat Intelligence

CVE-2026-15553: Ragic Enterprise Cloud Database arbitrary file upload

CVE-2026-15553 · Severity: medium · CVSS 5.3 · Published 2026-07-13

Technologies: Ragic Enterprise Cloud Database. Vendors: Ragic.

Executive brief

Ragic Enterprise Cloud Database, a platform used by businesses to build custom database applications, contains a security flaw that allows unauthorized individuals to upload files to the system. An attacker could use this to host malicious software or deceptive files on the company's trusted database environment. If other users download these files, it could lead to malware infections or further security compromises within the organization.

Technical details

An arbitrary file upload vulnerability (CWE-434) exists in Ragic Enterprise Cloud Database due to insufficient validation of user-supplied files. An unauthenticated remote attacker can exploit this by sending a specially crafted request to upload files to the server. While the primary impact is the ability to host and distribute malicious content to other users, the lack of authentication makes this a significant integrity risk. Cloud-hosted versions have been patched by the vendor; on-premises users must apply the patch released on or after April 10, 2026.

Affected products

  • Ragic Enterprise Cloud Database All versions prior to April 10, 2026 patch (on-premises)

Timeline

  • 2026-04-10: patched: Patch released for on-premises versions; cloud version updated.
  • 2026-07-13: advisory: Public advisory issued by TWCERT/CC.

References

Related threats