CVE-2026-41587 | ci4-cms-erp ci4ms up to 0.31.5.0 ZIP File public/ unrestricted upload (GHSA-fw49-9xq4-gmx6)
A vulnerability was found in ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0/0.31.4.0/0.31.5.0 and classified as critical. This affects an unknown part of the file public/ of the component ZIP File Handler. Executing a manipulation can lead to unrestricted upload.
This vulnerability is tracked as CVE-2026-41587. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.