CVE-2026-71379
published 2026-09-29CVE-2026-71379: The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.
PriorityP272critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.44%
36.2th percentile
The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| toptech_systems | tms7 | — | — |
| toptech_systems | tophat | — | — |
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv4.010.0CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.
ghsa_unreviewed·2026-09-30
CVE-2026-71379 [CRITICAL] CWE-552 The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.
The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.
VulDB
Toptech Systems TopHAT/TMS7 up to 7.6.3/7.7 Export Endpoint information disclosure
vuldb·2026-09-29·CVSS 10.0
CVE-2026-71379 [CRITICAL] Toptech Systems TopHAT/TMS7 up to 7.6.3/7.7 Export Endpoint information disclosure
A vulnerability described as problematic has been identified in Toptech Systems TopHAT and TMS7 up to 7.6.3/7.7. Affected by this issue is some unknown functionality of the component Export Endpoint. Executing a manipulation can lead to information disclosure.
This vulnerability appears as CVE-2026-71379. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-29
Published