Junglewise Threat Intelligence

CVE-2026-6847: 4real ThemisNETPanel remote code execution via unauthenticated file upload

CVE-2026-6847 · Severity: info · CVSS 9.3 · Published 2026-07-13

Executive brief

A critical security flaw has been identified in ThemisNETPanel, a management interface developed by 4real. The software contains a publicly accessible file upload feature that does not require a password or any form of authentication. An attacker can use this to upload malicious scripts and take complete control of the server, potentially leading to data theft, service disruption, or further network intrusion.

Technical details

A Remote Code Execution (RCE) vulnerability (CWE-306) exists in 4real ThemisNETPanel due to a lack of authentication on a critical file upload endpoint. The application exposes a specific endpoint that accepts base64-encoded payloads, allowing an unauthenticated remote attacker to upload arbitrary PHP files to the web server. Because the uploaded files can be directly accessed and executed by the PHP interpreter, an attacker can achieve full system compromise. The vulnerability is exploitable over the network without user interaction. A patch addressing this issue was released in April 2026.

Affected products

  • 4real ThemisNETPanel All versions prior to April 2026 (04.2026)

Timeline

  • 2026-04: patched: A patch was released by the vendor.
  • 2026-07-13: disclosed: Vulnerability details published by CERT.PL and NVD.

References