CVE-2026-40746 identifies a critical vulnerability in the restaurant_zone platform, affecting versions 0.7.8 and earlier. The flaw enables authenticated subscribers to upload arbitrary files to restricted server directories, potentially allowing remote code execution or data exfiltration. This vulnerability poses a severe risk to any organization utilizing the affected software, as exploitation could lead to full system compromise. The CVSS score of 9.9 reflects the high exploitability and impact potential. Attackers requiring only valid subscriber credentials could leverage this issue to deploy malicious payloads, bypassing standard access controls. Organizations must prioritize applying the vendor-released patch to mitigate this risk. Until patched, administrators should disable subscriber file upload capabilities and restrict directory permissions to prevent exploitation. Users are advised to verify their software versions and implement immediate remediation to avoid potential breaches. This vulnerability underscores the importance of timely patch management for third-party applications.
CRITICAL
CVSS 9.9
CVE-2026-40746
2026-08-23
Critical Vulnerability in Restaurant Zone Allows Arbitrary File Upload (CVE-2026-40746)
A critical vulnerability in restaurant_zone platform versions <= 0.7.8 allows attackers to perform arbitrary file uploads via subscriber features. CVSS 9.9. Immediate patching required to prevent remote code execution and data compromise.