Machine-generated analysis · WAYSCloud LLM
Toptech TMS7 and TopHAT version 7.6.3 are vulnerable to unauthenticated database export. The vendor released version 7.8 that resolves the issues.
Context
The advisory concerns Toptech Systems' TMS7 and TopHAT software, version 7.6.3. An unauthenticated attacker can export arbitrary database tables via the file export endpoint. Toptech addressed the vulnerabilities in release 7.8, available through their security blog.
Operator considerations
Check: Verify the installed version of TMS7 and TopHAT.
Isolate: Restrict external access to the file export endpoint if upgrade is delayed.
Patch: Upgrade to version 7.8, which contains the fixes.
Log: Monitor POST requests to the file export endpoint for unexpected activity.
Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code.
The following versions of Toptech TMS7 and TopHAT are affected:
TMS7 7.6.3 (CVE-2026-71379, CVE-2026-70356, CVE-2026-72510, CVE-2026-63713, CVE-2026-68954, CVE-2026-68068, CVE-2026-72507, CVE-2026-71302, CVE-2026-69662, CVE-2026-71189)
TopHAT 7.6.3 (CVE-2026-71379, CVE-2026-70356, CVE-2026-72510, CVE-2026-63713, CVE-2026-68954, CVE-2026-68068, CVE-2026-72507, CVE-2026-71302, CVE-2026-69662, CVE-2026-71189)
Vendor
Equipment
Toptech Systems
Toptech TMS7 and TopHAT
Files or Directories Accessible to External Parties, Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), Session Fixation, Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'), Impr...
Read the full advisory on CISA →