CVE-2026-1331
Last modified
CVE-2026-1331 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hamastar | Meetinghub Paperless Meetings | < 2025-12-10 |
References
- https://www.twcert.org.tw/en/cp-139-10651-ff09c-2.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-10650-a5ee9-1.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-1331?
How severe is CVE-2026-1331?
How do I fix CVE-2026-1331?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1330MeetingHub developed by HAMASTAR Technology has an Arbitrary…8.7
- CVE-2026-13305Autel MaxiCharger AC Elite Home Software Update Improper Ver…6.4
- CVE-2026-13306Autel MaxiCharger AC Elite Home USB Authentication Bypass Vu…4.3
- CVE-2026-13307Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overfl…6.8
- CVE-2026-13308Autel MaxiCharger AC Elite Home WebSockets Integer Underflow…8.1
- CVE-2026-13309Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overf…6.8
- CVE-2026-13311shell-quote prior to 1.8.5 finalizes parsed tokens in parse(…8.7
- CVE-2026-13314Malicious HTML content could be injected into the content re…2
- CVE-2026-13316A flaw has been found in foreman when HTTP parameters are mo…4.4
- CVE-2026-13318A server-side request forgery (SSRF) flaw was found in KubeV…6.4
- CVE-2026-1332MeetingHub developed by HAMASTAR Technology has a Missing Au…6.9
- CVE-2026-13320GitLab has remediated an issue in GitLab CE/EE affecting all…5.4
Are you affected by CVE-2026-1331?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
