CVE-2026-1358: Airleader GmbH Airleader Master
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.
Affected products
- Airleader GmbH Airleader Master: up to and including 6.381
Published 2026-02-12. Last modified 2026-06-17.