CriticalCritical vulnerability
CVE-2026-89040 (CVSS 9.3)
NVD · officialPublished Sep 15, 2026Risk 50/100EPSS 0.9%
Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.
Technical details
CVSS
9.3
AV:NetworkAC:LowPR:NoneUI:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source