---
id: CVE-2026-102263
title: >-
  A vulnerability has been found in mwasikz robo-cafe-rms up to
  228c44a02823f04e85db32b7137809a2856148fc
summary: >-
  A vulnerability has been found in mwasikz robo-cafe-rms up to
  228c44a02823f04e85db32b7137809a2856148fc. The affected element is an unknown
  function of the file manage-food.php. Such manipulation leads to unrestricted
  upload. The attack m…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-284
  - CWE-434
vendor: mwasikz
product: robo-cafe-rms
affected:
  - robo-cafe-rms 228c44a02823f04e85db32b7137809a2856148fc
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T05:16:58.867'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102263'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-102263'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/939874'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/411165'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/411165/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T04:27:15.488Z'
---

## Overview

A vulnerability has been found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The affected element is an unknown function of the file manage-food.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
