TVN ID: TVN-202601008 CVE IDs: CVE-2026-1330, CVE-2026-1331, CVE-2026-1332 CVSS Scores: - CVE-2026-1330: 7.5 (High) - CVE-2026-1331: 9.8 (Critical) - CVE-2026-1332: 5.3 (Medium) Affected Products: MeetingHub (with attendance module installed) Descriptions: - CVE-2026-1330: Arbitrary File Read vulnerability; remote attackers can exploit Absolute Path Traversal to download arbitrary system files. - CVE-2026-1331: Arbitrary File Upload vulnerability; remote attackers can upload and execute web shell backdoors, enabling arbitrary code execution on the server. - CVE-2026-1332: Missing Authentication vulnerability; remote attackers can access specific API functions and obtain meeting-related information. Solution: Install the patch with version 20251210 or later. Credit: Alan Chung (DEVCORE) Public Date: 2026-01-22