Executive brief
Sparx Pro Cloud Server, a platform used to host and share Enterprise Architect models, contains a vulnerability that could allow an attacker to take full control of the server. By exploiting a timing issue during file processing, an authorized user can upload and execute malicious code. This could lead to the theft of sensitive architectural designs, data corruption, or a complete compromise of the server environment.
Technical details
A race condition exists in the /data_api/dl_internal_artifact.php endpoint of Sparx Pro Cloud Server. The application downloads object properties based on a user-supplied GUID and temporarily saves the content to the local directory (__DIR__) using a user-controlled filename. While the application attempts to delete this file after processing, an attacker can exploit a race condition by delaying the response transmission (e.g., via a slow connection or large file). During this window, the attacker can send a second request to execute the newly created PHP file. Successful exploitation requires repository access but results in full remote code execution (RCE) under the context of the web server. Versions up to 6.1 (build 167) are confirmed vulnerable.
Affected products
- Sparx Systems Pro Cloud Server All versions through 6.1 (build 167)
Timeline
- 2026-05-19: advisory: Advisory published by CERT Polska
- 2026-05-19: disclosed