Executive brief
Borg SPM 2007, a legacy business process management system, contains a critical security flaw that allows unauthorized individuals to upload files to the server. By exploiting this vulnerability, an attacker can install a 'web shell' to take complete control of the server remotely. This could lead to the theft of sensitive corporate data, total service disruption, or the use of the server as a jumping-off point for further attacks on the internal network.
Technical details
Borg SPM 2007 is vulnerable to an unrestricted file upload (CWE-434). The application fails to properly validate or restrict the types of files uploaded to the server, allowing an unauthenticated remote attacker to upload malicious scripts, such as web shells. Once uploaded, these scripts can be executed in the context of the web server, leading to full system compromise and arbitrary code execution. While the product reached end-of-sale in 2008, the vendor recommends that customers with active maintenance contracts contact them for patching or upgrade to SPM2025 SP1.
Affected products
- BorG Technology Corporation Borg SPM 2007 All versions (Sales ended in 2008)
Timeline
- 2026-04-23: disclosed: Initial disclosure by TWCERT/CC
- 2026-04-23: advisory: NVD published CVE-2026-6885