CVE-2026-27419 describes a critical vulnerability in Zegen platform versions 1.1.9 and earlier, enabling attackers to perform arbitrary file uploads through subscriber endpoints. This flaw allows unauthorized users to bypass security controls and upload malicious files, potentially leading to remote code execution, data exfiltration, or system compromise. All instances of the Zegen platform using affected versions are at risk. The CVSS score of 9.9 reflects the severe impact and exploitability of this vulnerability. Attackers requiring no authentication could exploit this issue to gain full control over affected systems. Organizations deploying the Zegen platform must prioritize applying the latest security patches to mitigate this risk. Immediate action is recommended to audit system configurations, restrict unnecessary subscriber permissions, and implement additional input validation controls until a patch is applied. Users are advised to consult official advisories for specific remediation steps and verify compatibility with their operational environment.
CRITICAL
CVSS 9.9
CVE-2026-27419
2026-08-21
Critical Vulnerability in Zegen Platform Allows Arbitrary File Upload (CVE-2026-27419)
A critical vulnerability in Zegen platform versions <=1.1.9 allows attackers to upload arbitrary files via subscriber endpoints. This poses a high risk of remote code execution and data compromise. Immediate mitigation is required.