Junglewise Threat Intelligence

CVE-2026-24727: SUNNET Corporate Training Management System unrestricted upload in e-paper draft function

CVE-2026-24727 · Severity: info · CVSS 9.3 · Published 2026-07-24

Executive brief

SUNNET Corporate Training Management System is a platform used by organizations to manage employee learning and development. A security vulnerability in the e-paper draft upload feature allows an administrator to upload malicious files disguised as ZIP archives. If exploited, this could allow the attacker to take full control of the server and execute unauthorized commands, potentially leading to data theft or service disruption.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the e-paper draft upload function of the SUNNET Corporate Training Management System through version 10.3. The root cause is insufficient validation of file types within uploaded ZIP archives. A remote authenticated attacker with administrator privileges can exploit this by uploading a crafted ZIP archive containing server-executable files. Successful exploitation allows for arbitrary command execution on the underlying server. The vulnerability has been assigned a CVSS 4.0 score of 9.3 by the reporting CNA.

Affected products

  • SUNNET Technology Co., Ltd. Corporate Training Management System through v10.3

Timeline

  • 2026-07-24: disclosed: Initial disclosure and NVD publication

References