critical

Unrestricted File Upload (Web Shell) in Başarsoft Rotaban — CVE-2026-11839

critical-cve-against-infra · active

A critical unrestricted file upload vulnerability in Başarsoft Information Technologies' Rotaban allows an attacker to upload a web shell to the web server, leading to remote code execution. The issue affects Rotaban from V2026.06.002 before V2026.06.003.

Affected packages

Sources