Skip to content
Threat Feed
high advisory

Unrestricted File Upload Vulnerability in Eimzamip

The Eimzamip application (versions 1.6.4 through 1.6.5) is vulnerable to an unrestricted file upload flaw allowing remote attackers to upload malicious file types, potentially leading to unauthorized code execution.

CVE search metadata

CVE search record: CVE-2026-91844. Severity: high. CVSS: 7.3. KEV: no. Product: Eimzamip (1.6.4 - 1.6.5). Brief: Unrestricted File Upload Vulnerability in Eimzamip. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-91844/

The Eimzamip application, developed by İzometri IT Services Domestic and Foreign Trade Co. Ltd., contains a security vulnerability categorized as an unrestricted upload of files with dangerous types. This flaw, tracked as CVE-2026-91844, affects versions 1.6.4 and 1.6.5. By failing to properly validate or restrict the file extensions and content of uploaded files, the application allows unauthorized parties to place malicious files onto the server. If an attacker successfully leverages this vulnerability, they may be able to execute arbitrary code within the context of the application server, potentially leading to a full system compromise. Users of the affected software are urged to upgrade to version 1.6.6 or later to remediate this vulnerability.

Impact

Successful exploitation of CVE-2026-91844 allows for the introduction of malicious files into the application environment. This can result in remote code execution, unauthorized access to sensitive data processed by the Eimzamip service, or the use of the server as a pivot point for further network propagation. The impact is assessed as high due to the potential for unauthenticated remote exploitation.

Recommendation

  1. Upgrade Eimzamip to version 1.6.6 or later immediately to address CVE-2026-91844.
  2. Implement strict server-side validation for all file uploads, ensuring that only expected file extensions and MIME types are accepted.
  3. Store uploaded files in a non-executable directory and configure the web server to disable script execution in upload folders.
  4. Perform a security review of current application logs for any suspicious POST requests targeting upload endpoints followed by attempts to access these files directly.