Junglewise Threat Intelligence

CVE-2026-9157: Gmission Web Fax unrestricted file upload in Web Fax

CVE-2026-9157 · Severity: high · CVSS 8.4 · Published 2026-05-21

Executive brief

Gmission Web Fax, a digital faxing solution, contains a security vulnerability that allows for the unauthorized upload of dangerous files. An attacker could exploit this to execute malicious code on the system, potentially leading to a full system takeover, data theft, or service disruption. This issue affects versions 3.0 through 3.1 of the software.

Technical details

Gmission Web Fax (versions 3.0 to 3.1) suffers from a vulnerability involving improper input validation (CWE-20) and unrestricted upload of files with dangerous types (CWE-434). The flaw allows an attacker to perform Remote Code Inclusion (RCI) by uploading malicious files to the server. While the CVSS vector (AV:L) suggests a local attack vector, the nature of the 'Web Fax' component typically implies a network-accessible interface; however, based strictly on the provided metadata, the attack is classified as local. Successful exploitation grants the attacker the ability to execute arbitrary code with the privileges of the web service, compromising confidentiality, integrity, and availability.

Affected products

  • Gmission Web Fax 3.0 to 3.1

Timeline

  • 2026-05-21: advisory: NVD publication date

References

Related threats