Executive brief
Sunnet CTMS and CPAS, which are enterprise platforms used for corporate training and performance management, contain a security flaw that allows an authorized user with high-level privileges to upload malicious files. By exploiting this vulnerability, an attacker can install a 'web shell' to take full control of the server. This could lead to the theft of sensitive employee data, total service disruption, or the use of the server as a jumping-off point for further attacks on the corporate network.
Technical details
Sunnet CTMS and CPAS suffer from an unrestricted file upload vulnerability (CWE-434). The flaw allows a remote attacker with high privileges (such as an administrator) to upload files with dangerous extensions to the web server. Because the application fails to properly validate or sanitize uploaded file types, the attacker can upload a web shell and execute it in the context of the server. This results in full arbitrary code execution (RCE) on the underlying host. The vulnerability affects all versions of both products, and while a patch is expected from the vendor, users are advised to contact Sunnet directly for updates.
Affected products
- Sunnet CTMS (Corporate Training Management System) All versions
- Sunnet CPAS (Corporate Performance Appraisal System) All versions
Timeline
- 2026-04-30: disclosed: Vulnerability disclosed by TWCERT/CC
- 2026-05-02: advisory: CVE-2026-7490 published to NVD