S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 10, 2026

CVE-2026-2113 Scanner

CVE-2026-2113 Scanner - Remote Code Execution vulnerability in tpadmin

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-2113
6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component WebUploader. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
tpadminby yuan1994
1.3.0
Updated Sep 10, 2026View on NVD →
Detail

The tpadmin software is a web-based administrative tool used in various organizations for managing content and settings on web servers. It is developed by yuan1994 and utilized for its user-friendly interface and flexibility in managing website content and server configurations. It serves the needs of system administrators and developers who require efficient control over their web applications without delving deep into code. The software's focus on ease of use makes it a popular choice for small to medium-sized enterprises seeking efficient site management solutions. Users can rely on tpadmin to handle daily administrative tasks, streamline workflows, and ensure seamless web operations. However, due to vulnerabilities like Remote Code Execution, it requires careful monitoring and timely updates to maintain security integrity.

Remote Code Execution (RCE) is a critical vulnerability that enables attackers to execute arbitrary code on a target system. This vulnerability, once exploited, allows remote and unauthenticated attackers to take control over the server by running malicious scripts. It poses a significant threat as it can lead to full system compromise, disrupting services and exposing sensitive data. The vulnerability often arises due to improper input validation, allowing attackers to inject harmful code. When exploited, it gives the attacker the same permissions as the running server, often leading to unauthorized data manipulation or theft. Effective detection and remediation are crucial to prevent exploitation and safeguard the affected systems.

The vulnerable endpoint in tpadmin's file "preview.php" allows attackers to upload files without adequate security checks. The WebUploader preview component lacks proper validation, leading to a situation where base64-encoded PHP payloads can be submitted by an attacker. This payload then gets executed with the privileges of the web server. The flaw lies in the unrestricted file upload capability that fails to differentiate between benign and malicious files. Attackers typically aim to upload scripts that execute their commands, thus gaining control over the web application. Detailed examination reveals that the vulnerability can be triggered through unauthenticated HTTP POST requests to the preview endpoint.

If exploited, the Remote Code Execution vulnerability can have severe implications for affected systems and organizations. Attackers can execute arbitrary PHP code on the server, gaining access to sensitive information or modifying critical server settings. The risk of data theft, unauthorized access to user accounts, and financial loss increases significantly. There is also the danger of installing backdoors for persistent access, leading to ongoing exploitation. Organizations may face disruption of services, loss of customer trust, and compliance violations. Timely patching and robust security practices are essential to mitigate such risks.

REFERENCES

Solution Advice
  • Apply updates or patches provided by the vendor immediately.
  • Restrict access to vulnerable scripts like "preview.php" through server configuration settings.
  • Ensure strict validation of file uploads to prevent malicious code from being processed.
  • Implement monitoring for unusual activities indicating exploitation attempts.
  • Review and enhance the overall security posture of the application and its hosting environment.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2026-2113 Scanner - Remote Code Execution vulnerability in tpadmin | S4E