CVE-2026-67243: Refirio FREO2

High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.

Affected products

  • Refirio FREO2: before 2.0.0-alpha-14 (fixed in 2.0.0-alpha-14)

Published 2026-08-04. Last modified 2026-08-28.