Unrated severityNVD Advisory· Published Jul 5, 2026· Updated Jul 6, 2026
Ruijie RG-UAC user_auth_commit.php unrestricted upload
CVE-2026-14736
Description
A vulnerability was found in Ruijie RG-UAC up to 1.0-R1.8.2.p5. The impacted element is an unknown function of the file user_auth_commit.php. Performing a manipulation of the argument upload_image results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Affected products
1- Range: <=1.0-R1.8.2.p5
Patches
Vulnerability mechanics
References
5- ucn9h68n9289.feishu.cn/wiki/OiAKwH3hRi3oVpkQyeycjjPrnL8mitreexploit
- vuldb.com/cve/CVE-2026-14736mitrethird-party-advisory
- vuldb.com/submit/848624mitrethird-party-advisory
- vuldb.com/vuln/376318mitrevdb-entrytechnical-description
- vuldb.com/vuln/376318/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.