Summary
CVE-2026-16286 is a critical unrestricted file upload vulnerability in TRtek’s Software Repository Management application. The flaw allows an unauthenticated remote attacker to upload a web shell to the server, resulting in full remote code execution. It carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: The application (CWE-434: Unrestricted Upload of File with Dangerous Type) fails to properly validate or restrict the type of files submitted through its upload functionality.
- Trigger conditions: An attacker submits a crafted file (e.g., a web shell) through the affected upload feature.
- Attack vector: Network-based, no authentication (PR:N) or user interaction (UI:N) required, low attack complexity (AC:L).
- Impact: Successful exploitation grants full remote code execution on the server, with high impact to confidentiality, integrity, and availability.
Affected software
- TRtek Software Repository Management — all versions/builds prior to commit
2fb4acee.
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade to a build of TRtek Software Repository Management that incorporates commit
2fb4aceeor later; confirm with the vendor that the deployed build includes this fix. - If no patch is available: Restrict network access to the application to trusted internal networks or a VPN — do not expose the upload functionality directly to the internet; deploy a WAF rule to block uploads of executable file types (e.g.,
.php,.jsp,.asp,.aspx) or files with mismatched content-type/extension pairs; monitor upload directories for newly created executable files and review web server logs for suspicious POST requests.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
class="program-adi">TRtek Web HBYS<,<h3>TRtek Web HBYS</h3>,TRtek Web HBYS, Kurumların ihtiyaçlarını karşılamak amacıyla geliştirilmiştir.

