PatchSiren cyber security CVE debrief
CVE-2026-105389 feelec-yishu CVE debrief
CVE-2026-105389 is a security vulnerability detected in feelec-yishu feelcrm-os 1.0.0. The issue affects the UploadTicketFile Endpoint in the UploadController.class.php file, allowing for unrestricted upload. The attack can be launched remotely, and the exploit has been disclosed publicly. The project was informed early but has not responded yet. This vulnerability has a medium severity level and requires immediate attention from defenders responsible for feelcrm-os 1.0.0 systems, especially those with publicly accessible UploadTicketFile Endpoints.
- Vendor
- feelec-yishu
- Product
- feelcrm-os
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for feelcrm-os 1.0.0 systems, especially those with publicly accessible UploadTicketFile Endpoints, should assess exposure and prioritize verification and remediation.
Why it matters
CVE-2026-105389 is a medium-severity vulnerability in feelcrm-os 1.0.0 that allows for unrestricted upload. Defenders should prioritize verifying exposure, especially for publicly accessible systems, and assess the need for compensating controls or monitoring. The exploit has been disclosed publicly, increasing the risk of exploitation.
- Potential for malicious file uploads
- Risk of remote exploitation and potential system compromise
- Need for verification of exposure and implementation of compensating controls
Technical summary
The vulnerability affects the UploadTicketFile Endpoint in the UploadController.class.php file of feelcrm-os 1.0.0. The issue allows for unrestricted upload, which can be exploited remotely. The exploit has been disclosed publicly. This vulnerability has a medium severity level and requires immediate attention from defenders responsible for feelcrm-os 1.0.0 systems, especially those with publicly accessible UploadTicketFile Endpoints. The attack can lead to potential system compromise and requires verification of exposure and implementation of compensating controls.
Defensive priority
Defenders should prioritize verifying exposure of feelcrm-os 1.0.0 systems, especially those with publicly accessible UploadTicketFile Endpoints, and assess the need for compensating controls or monitoring.
Recommended defensive actions
- Verify exposure of feelcrm-os 1.0.0 systems, especially those with publicly accessible UploadTicketFile Endpoints
- Assess the need for compensating controls or monitoring
- Review and implement secure upload practices for the affected component
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected version, and references. However, the corpus lacks specific information on exploitation, impact, or remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105389 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105389
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105389 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105389
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
feelec-yishu feelcrm-os UploadTicketFile Endpoint UploadController.class.php unrestricted upload
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105389.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413583
Supplemental source - vdb-entry, technical-description
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413583/cti
Supplemental source - signature, permissions-required
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-105389
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/979554
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/feelec-yishu/feelcrm-os/issues/7
Supplemental source - exploit, issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/feelec-yishu/feelcrm-os/
Supplemental source - product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.