Skip to content
CVSS 7.2 · HIGH

CVE-2026-7490

CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

View on NVD

Analysis

Sunnet CTMS and CPAS are highly specialized clinical trial management systems. The vulnerability requires existing privileges and the software is not part of the common open-source or enterprise stack used by the general development community.

Severity

Score: 7.2(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: HIGH
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-434

EPSS

Probability of exploitation (next 30 days): 0.0021 (0.2%)
Percentile: 43.4%
EPSS: 2026-05-06

Technical description

CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Published: 5/2/2026, 10:16:18 AM
Last modified: 5/5/2026, 8:14:57 PM

References

HomeEventsBlogResourcesTeam