{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aizometri_it_services_domestic_and_foreign_tradeeimzamip/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:izometri_it_services_domestic_and_foreign_trade:eimzamip:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-91844"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Eimzamip (1.6.4 - 1.6.5)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","file-upload"],"_cs_type":"advisory","_cs_vendors":["İzometri IT Services Domestic and Foreign Trade Co. Ltd."],"content_html":"\u003cp\u003eThe Eimzamip application, developed by İzometri IT Services Domestic and Foreign Trade Co. Ltd., contains a security vulnerability categorized as an unrestricted upload of files with dangerous types. This flaw, tracked as CVE-2026-91844, affects versions 1.6.4 and 1.6.5. By failing to properly validate or restrict the file extensions and content of uploaded files, the application allows unauthorized parties to place malicious files onto the server. If an attacker successfully leverages this vulnerability, they may be able to execute arbitrary code within the context of the application server, potentially leading to a full system compromise. Users of the affected software are urged to upgrade to version 1.6.6 or later to remediate this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-91844 allows for the introduction of malicious files into the application environment. This can result in remote code execution, unauthorized access to sensitive data processed by the Eimzamip service, or the use of the server as a pivot point for further network propagation. The impact is assessed as high due to the potential for unauthenticated remote exploitation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Eimzamip to version 1.6.6 or later immediately to address CVE-2026-91844.\u003c/li\u003e\n\u003cli\u003eImplement strict server-side validation for all file uploads, ensuring that only expected file extensions and MIME types are accepted.\u003c/li\u003e\n\u003cli\u003eStore uploaded files in a non-executable directory and configure the web server to disable script execution in upload folders.\u003c/li\u003e\n\u003cli\u003ePerform a security review of current application logs for any suspicious POST requests targeting upload endpoints followed by attempts to access these files directly.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-08T15:15:52Z","date_published":"2026-10-08T15:15:52Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-91844/","summary":"The Eimzamip application (versions 1.6.4 through 1.6.5) is vulnerable to an unrestricted file upload flaw allowing remote attackers to upload malicious file types, potentially leading to unauthorized code execution.","title":"Unrestricted File Upload Vulnerability in Eimzamip","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-91844/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:izometri_it_services_domestic_and_foreign_trade:eimzamip:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}