cvedb.io
CVE-2026-33560
HIGH · CVSS 7.1
EPSS exploitation probability: 0%
Published 2026-06-26T23:17:08.847 · Last modified 2026-06-29T19:24:30.707

Summary

The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.