---
id: CVE-2026-89040
title: >-
  Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated
  attacker to send a crafted POST request including ../ and gain root access on
  the target device
summary: >-
  Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated
  attacker to send a crafted POST request including ../ and gain root access on
  the target device. An attacker who uploads a webshell can execute arbitrary
  code…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: Tencent
product: Mass Service Engine in Cluster (MSEC)
affected:
  - mass_service_engine_in_cluster_msec < *
published: '2026-09-15'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T17:17:28.647'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89040'
references:
  - url: 'https://github.com/Tencent/MSEC'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-258-02.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89040'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
epss: 0.01144
epssPercentile: 0.65273
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-22T16:22:29.446485Z'
ingestedAt: '2026-09-15T20:44:02.608Z'
---

## Overview

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
