CVE-2026-89040
—Unauthenticated Path Traversal to Root Code Execution in Tencent MSEC
Tencent's Mass Service Engine in Cluster (MSEC) contains an unauthenticated path traversal flaw (CWE-22) that lets a remote attacker send a crafted POST request containing '../' sequences to write files outside the intended directory, such as a webshell. Once a webshell is uploaded, the attacker can execute arbitrary code with root privileges on the target device, giving full compromise of confidentiality, integrity, and availability. The attack requires no credentials and no user interaction, and is rated critical at CVSS 4.0 9.3. Any organization running an internet-reachable MSEC deployment is affected; no affected or fixed version numbers have been published. There is no known public proof of concept, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported to date.
What to do: Immediately inventory for any Tencent MSEC deployments and remove or isolate management/API endpoints from the public internet (allow-list via VPN or firewall). Review web server and MSEC logs for POST requests containing '../' sequences and hunt for unexpected recently-added script/webshell files and unexplained root processes. Contact Tencent or monitor their advisories for a patched release, since no fixed version has been specified in the available data.
| Tencent Mass Service Engine in Cluster (MSEC) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.
- Weakness
- CWE-22
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.