A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06 . It has been declared as critical . This impacts an unknown function of the file /common/jsp/upload3.jsp . Executing a manipulation of the argument File can lead to unrestricted upload. The identification of this vulnerability is CVE-2026-8758 . The attack may be launched remotely. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any way.