PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66627 EDGE22 Studios Ltd. CVE debrief

CVE-2026-66627: Unrestricted File Upload with Dangerous Type in GP Premium allows for remote code execution. This critical vulnerability affects GP Premium from n/a through 2.5.5, with a CVSS score of 9.9. Defenders and security teams should assess exposure and prioritize remediation to prevent potential security breaches. The vulnerability enables attackers to upload malicious files, leading to possible system compromise and data breaches. Review and update GP Premium to version 2.5.6 or later, restrict file uploads to specific validated types, and implement additional security measures like web application firewalls.

Vendor
EDGE22 Studios Ltd.
Product
GP Premium
CVSS
CRITICAL 9.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-09-08
Advisory published
2026-08-18
Advisory updated
2026-09-08

Who should care

Defenders and security teams responsible for GP Premium installations should assess exposure and prioritize remediation. This vulnerability allows for remote code execution, which can lead to significant security breaches if exploited.

Why it matters

CVE-2026-66627 is a critical vulnerability in GP Premium that allows for remote code execution. Defenders and security teams responsible for GP Premium installations should assess exposure and prioritize remediation to prevent potential security breaches.

  • Remote code execution is possible, allowing attackers to gain control of affected systems
  • Unauthenticated attackers can exploit this vulnerability, increasing the attack surface
  • Successful exploitation can lead to data breaches, system compromise, and further malicious activity

Technical summary

The Unrestricted Upload of File with Dangerous Type vulnerability in GP Premium allows Remote Code Inclusion. The issue affects GP Premium from n/a through 2.5.5 and has a CVSS score of 9.9, classified as CRITICAL. This vulnerability enables remote code execution, allowing attackers to gain control of affected systems. Successful exploitation can lead to data breaches, system compromise, and further malicious activity. To mitigate, review and update GP Premium to version 2.5.6 or later, restrict file uploads to only allow specific validated file types, and enhance

Defensive priority

High

Recommended defensive actions

  • Review and update GP Premium to version 2.5.6 or later
  • Restrict file uploads to only allow specific, validated file types
  • Implement additional security measures, such as web application firewalls and intrusion detection systems

Evidence notes

The CVE record and NVD entry provide details on the Unrestricted Upload of File with Dangerous Type vulnerability in GP Premium, allowing Remote Code Inclusion. The issue affects GP Premium from n/a through 2.5.5.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-66627 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-66627

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-66627 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66627

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.