CVE-2026-1222
Last modified
CVE-2026-1222 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-1222?
How severe is CVE-2026-1222?
How do I fix CVE-2026-1222?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12213A vulnerability was found in hcengineering Huly Platform up …4.3
- CVE-2026-12214A security flaw has been discovered in Qihoo 360 Total Secur…7.8
- CVE-2026-12216A weakness has been identified in svaarala duktape up to 2.9…5.3
- CVE-2026-12217A security vulnerability has been detected in DVDFab Virtual…7.8
- CVE-2026-12218A vulnerability was detected in Yealink SIP-T46U 108.87.50.1…8
- CVE-2026-12219A flaw has been found in Yealink SIP-T46U 108.86.0.118. The …6.3
- CVE-2026-12220A vulnerability has been found in Yealink SIP-T46U 108.86.0.…8
- CVE-2026-12221A vulnerability was found in Yealink SIP-T46U 108.86.0.118. …8
- CVE-2026-12222A vulnerability was determined in Yealink SIP-T46U 108.86.0.…8
- CVE-2026-12223A vulnerability was identified in Yealink SIP-T46U 108.86.0.…5.5
- CVE-2026-12224The Dokan Pro plugin for WordPress is vulnerable to privileg…8.8
- CVE-2026-12225syracom AG Secure Login (2FA) for Atlassian Jira, Confluence…8.7
Are you affected by CVE-2026-1222?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
