PatchSiren cyber security CVE debrief
CVE-2026-66627 EDGE22 Studios Ltd. CVE debrief
CVE-2026-66627: Unrestricted File Upload with Dangerous Type in GP Premium allows for remote code execution. This critical vulnerability affects GP Premium from n/a through 2.5.5, with a CVSS score of 9.9. Defenders and security teams should assess exposure and prioritize remediation to prevent potential security breaches. The vulnerability enables attackers to upload malicious files, leading to possible system compromise and data breaches. Review and update GP Premium to version 2.5.6 or later, restrict file uploads to specific validated types, and implement additional security measures like web application firewalls.
- Vendor
- EDGE22 Studios Ltd.
- Product
- GP Premium
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-09-08
Who should care
Defenders and security teams responsible for GP Premium installations should assess exposure and prioritize remediation. This vulnerability allows for remote code execution, which can lead to significant security breaches if exploited.
Why it matters
CVE-2026-66627 is a critical vulnerability in GP Premium that allows for remote code execution. Defenders and security teams responsible for GP Premium installations should assess exposure and prioritize remediation to prevent potential security breaches.
- Remote code execution is possible, allowing attackers to gain control of affected systems
- Unauthenticated attackers can exploit this vulnerability, increasing the attack surface
- Successful exploitation can lead to data breaches, system compromise, and further malicious activity
Technical summary
The Unrestricted Upload of File with Dangerous Type vulnerability in GP Premium allows Remote Code Inclusion. The issue affects GP Premium from n/a through 2.5.5 and has a CVSS score of 9.9, classified as CRITICAL. This vulnerability enables remote code execution, allowing attackers to gain control of affected systems. Successful exploitation can lead to data breaches, system compromise, and further malicious activity. To mitigate, review and update GP Premium to version 2.5.6 or later, restrict file uploads to only allow specific validated file types, and enhance
Defensive priority
High
Recommended defensive actions
- Review and update GP Premium to version 2.5.6 or later
- Restrict file uploads to only allow specific, validated file types
- Implement additional security measures, such as web application firewalls and intrusion detection systems
Evidence notes
The CVE record and NVD entry provide details on the Unrestricted Upload of File with Dangerous Type vulnerability in GP Premium, allowing Remote Code Inclusion. The issue affects GP Premium from n/a through 2.5.5.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-66627 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-66627
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-66627 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66627
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.