PatchSiren cyber security CVE debrief
CVE-2026-1358 Airleader GmbH CVE debrief
CVE-2026-1358 is a critical Airleader Master vulnerability affecting version 6.381 and prior. According to the CISA CSAF advisory, multiple webpages allow unrestricted file uploads while running with maximum privileges, which could let an unauthenticated attacker potentially achieve remote code execution on the server. Airleader’s stated fix is version 6.386 or later.
- Vendor
- Airleader GmbH
- Product
- Airleader Master
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-12
- Original CVE updated
- 2026-02-12
- Advisory published
- 2026-02-12
- Advisory updated
- 2026-02-12
Who should care
Airleader Master administrators, OT/ICS operators, system integrators, and incident responders responsible for exposed Airleader deployments should treat this as high priority.
Technical summary
The advisory describes an unrestricted file upload weakness in Airleader Master versions 6.381 and earlier. Because affected webpages run with maximum privileges, a successful upload could lead to server-side code execution without authentication. The supplied CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8 Critical), indicating network reachability, no required privileges, and full impact if exploited.
Defensive priority
Immediate
Recommended defensive actions
- Upgrade Airleader Master to version 6.386 or later, as recommended by the vendor.
- If immediate upgrading is not possible, contact Airleader for mitigation assistance via the vendor’s published support channels.
- Limit exposure of Airleader Master interfaces to trusted administrative networks until remediation is complete.
- Review affected deployments for unexpected or unauthorized file uploads and any signs of server-side execution.
- Follow CISA ICS recommended practices referenced in the advisory for hardening and defense-in-depth measures.
Evidence notes
All substantive findings in this debrief come from the supplied CISA CSAF advisory ICSA-26-043-10 / CVE-2026-1358 source item and its embedded remediation guidance. The advisory was published and last modified on 2026-02-12T07:00:00Z. The supplied corpus does not identify KEV listing or ransomware-campaign association.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-1358 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-1358
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-1358 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-1358
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-043-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.