Executive brief
ImageMaster is an enterprise content management system used by organizations to manage, archive, and digitalize business documents and processes. This vulnerability allows authenticated users to upload executable files (such as PHP, HTML, or EXE) through the attachment feature when creating documents, which can then be executed by other users who view them—enabling unauthorized code execution and potential compromise of the document management system and connected data.
Technical details
A file upload validation vulnerability exists in ImageMaster's document creation feature, specifically in the "add attachments" function. The application fails to properly validate file type, content, and extension before accepting uploads, allowing an authenticated user to upload executable files with dangerous extensions (.php, .exe, .html, .jsp, etc.). When other users access the uploaded attachment through the "view attachment" feature, the file can be executed in the browser or server context, leading to stored XSS, arbitrary code execution, or both. The vulnerability requires authenticated access with write permissions but poses significant risk as uploaded files are accessible to other application users. No patch status has been confirmed in the advisory.
Affected products
- T-Systems International GmbH ImageMaster 9.14.2.8.1
Timeline
- 2026-08-17: disclosed: CVE-2026-50768 published
- 2025-10-14: other: Vulnerable build number 2025-10-14_07-34-43 identified