CRITICAL
SMEWebify
CVE published 2026-08-13
CVE-2026-49827
CVE-2026-49827 is a critical vulnerability in WebErpMesv2, a Resource Management and Manufacturing execution system Web for industry. The vulnerability allows any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. This chain is effectively unauthenticated RCE against any default installation due to open registration and broken r [truncated]