Overview
Toptech Systems, a vendor of terminal automation software for the fuel and bulk-liquid terminal industry, is affected by CVE-2026-70356, a critical unrestricted file upload vulnerability in its TMS7 and TopHAT products. According to CISA's ICS advisory ICSA-26-272-02, published September 29, 2026, "the TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server."
The flaw carries a CVSS 3.1 score of 9.1 (Critical), vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, and a CVSS 4.0 score of 9.4 (Critical), vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H. The Privileges Required: High (PR:H) designation means this is not an anonymous, pre-authentication bug — an attacker needs an already highly privileged account on the TMS7 or TopHAT web application to reach the vulnerable upload path. Once that bar is met, however, the outcome is a full, network-reachable remote code execution primitive: arbitrary PHP dropped onto the web server and executed at will.
TMS7 ("Terminal Management System") is Toptech's browser-based platform for automating fuel and bulk-liquid terminal operations — stock accounting, allocations, and remote control of entry gates, load racks, and bill-of-lading (BOL) printers, integrated with customer ERP and SCADA systems. Toptech describes TMS7 as deployed at over 1,200 terminals worldwide across barge, rail, truck-loading, liquefied-gas, asphalt, and chemical-plant applications. TopHAT is the companion product that centralizes management and reporting across a customer's entire portfolio of TMS7 sites — meaning a single compromised TopHAT deployment can be a pivot point into many terminals at once.
The vulnerability was reported by Sachin Shetty and Roy Duisters of Shell CyberDefence. Toptech Systems notified customers directly on July 20, 2026 — ahead of the public CISA disclosure — and the issue is fixed in release 7.8. CVE-2026-70356 was published as part of a larger CISA bulletin covering ten distinct TMS7/TopHAT vulnerabilities, including a CVSS 10.0 unauthenticated database export flaw (CVE-2026-71379), several SQL injection issues, a session-fixation bug, an eval-injection flaw, and a cross-site scripting issue — all tracked under advisory ICSA-26-272-02.
Technical Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-70356 |
| Severity | Critical |
| CVSS Score | 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) — also 9.4 under CVSS 4.0 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) |
| Attack Vector | Network |
| Authentication | Required — attacker must already hold a high-privileged (PR:H) account on the TMS7/TopHAT web application |
| Privileges Required | High — no user interaction required (UI:N) once that access is held |
| CWE | CWE-434 — Unrestricted Upload of File with Dangerous Type |
| Component/Function | TMS file upload endpoint (web application layer) |
| Vendor | Toptech Systems |
| Affected Products | TMS7 and TopHAT, version 7.6.3 |
| Fixed In | TMS7 / TopHAT release 7.8 |
| Exploit Status | No confirmed in-the-wild exploitation and no public proof-of-concept identified as of September 30, 2026; not listed on CISA's KEV catalog |
How It Works
The vulnerability class
CVE-2026-70356 is a textbook CWE-434 unrestricted file upload. The TMS file upload endpoint accepts a submitted file and writes it to a web-accessible location without validating the true file type — no MIME-type check, no extension allowlist, and apparently no enforcement that only non-executable content (images, PDFs, etc.) is permitted. Because the underlying web server will happily interpret a .php file dropped into a served directory, an attacker who can reach the endpoint can turn a simple "upload a file" feature into arbitrary PHP code execution.
The attack chain
- An attacker first obtains (or already holds) a high-privileged account on the TMS7 or TopHAT web interface — the
PR:Hrequirement in the CVSS vector means this is not exploitable by an anonymous or low-privilege user. - The attacker locates the TMS file upload endpoint and submits a file with a
.phpextension (or another server-executable extension) instead of an expected document or image type. - Because the endpoint performs no server-side type restriction, the file is accepted and written into a directory the web server will execute scripts from.
- The attacker requests the uploaded file directly by URL. The web server executes it as PHP, giving the attacker an interactive or persistent web shell running with the privileges of the web server process.
- The Scope Changed (
S:C) rating reflects that impact isn't confined to the upload feature itself — code execution on the TMS7/TopHAT host can be used to pivot into the underlying operating system, adjacent application data, and anything else that host can reach, including connected ERP/SCADA integrations.
Why this matters in a terminal-automation environment
TMS7 is purpose-built to remotely manage physical terminal equipment — entry gates, load racks, BOL printers — alongside stock-accounting and allocation data feeding customer ERP and SCADA systems. A web shell on a TMS7 host therefore sits closer to operational technology (OT) than a typical web-app compromise, and TopHAT's centralized, multi-site management makes one compromised instance a potential stepping stone into several terminals at once. It's also worth reading this CVE alongside the full ICSA-26-272-02 bulletin, which disclosed nine sibling flaws in the same codebase — notably CVE-2026-71379, a CVSS 10.0 unauthenticated database export bug that could plausibly hand an attacker the credentials needed to clear the PR:H bar required here. Defenders should remediate the bulletin as a set, not this CVE in isolation.
Impact Assessment
| Impact Area | Description |
|---|---|
| Remote Code Execution | Successful exploitation grants arbitrary PHP execution on the TMS7/TopHAT web server — a full web shell, not a limited read/write primitive |
| Confidentiality | Rated High — a web shell can read application data, terminal operational data, and any credentials or data reachable through connected ERP/SCADA integrations |
| Integrity | Rated High — an attacker could alter stock-accounting records, allocation data, or terminal-automation configuration |
| Availability | Rated High — a web shell could be used to disrupt or disable the TMS7/TopHAT application, and by extension the terminal functions it automates |
| OT-adjacent exposure | TMS7 directly manages physical equipment (entry gates, load racks, BOL printers); compromise of the application layer carries a realistic path to operational disruption at fuel and bulk-liquid terminals |
| Multi-site blast radius | TopHAT's centralized management of multiple TMS7 sites means one compromised TopHAT deployment can expose many terminals, not just one |
| Chaining risk | Part of a 10-vulnerability disclosure in the same advisory, including a CVSS 10.0 unauthenticated database export flaw (CVE-2026-71379) that could help an attacker meet this CVE's PR:H privilege bar |
Recommendations
For Toptech TMS7 / TopHAT administrators
- Inventory every TMS7 and TopHAT deployment and confirm its version. Toptech's advisory identifies 7.6.3 as affected and 7.8 as fixed; treat any instance earlier than 7.8 as exposed until confirmed otherwise.
- Upgrade to TMS7 / TopHAT 7.8 or later as a priority, following the change-management process from Toptech's July 20, 2026 customer advisory and CISA's ICSA-26-272-02 bulletin.
- Audit accounts with elevated TMS7/TopHAT privileges — since exploitation requires an already-privileged (
PR:H) account, review who holds elevated roles and look for unexplained escalations. - Restrict network exposure. TMS7 and TopHAT should never be directly internet-facing; place them behind a VPN or management-only segment, isolated from the terminal control network.
- Remediate the full advisory, not just this CVE — ICSA-26-272-02 covers nine other TMS7/TopHAT flaws that could plausibly be chained with this one.
For security teams
- Monitor web server logs for uploads of
.phpor other server-executable extensions to TMS7/TopHAT upload endpoints, and for requests to newly created files in upload directories. - Deploy a compensating WAF rule restricting the upload endpoint to an allowlist of non-executable content types (images, PDFs) pending the 7.8 upgrade.
- Treat TMS7/TopHAT as part of your OT/ICS attack surface — correlate application anomalies with operational alerts from the terminal equipment it controls, and subscribe to Toptech's and CISA's advisories for follow-on disclosures.
For terminal operators day-to-day
Report unfamiliar upload prompts or files, never share elevated TMS7/TopHAT credentials, and escalate unexpected gate, load-rack, or BOL-printer activity immediately — it could indicate compromise originating at the web application layer.
Key Takeaways
- CVE-2026-70356 is a Critical (CVSS 9.1, CVSS v4.0 9.4) unrestricted file upload flaw (CWE-434) in Toptech Systems TMS7 and TopHAT, published September 29, 2026 via CISA advisory ICSA-26-272-02.
- The TMS file upload endpoint performs no server-side file type validation, letting an attacker upload and execute arbitrary PHP — a direct path to a web shell and full server compromise.
- Exploitation requires an attacker to already hold a high-privileged account (
PR:H) — not an anonymous, pre-authentication bug — but the resulting compromise is complete across confidentiality, integrity, and availability. - Affected: version 7.6.3. Fixed: release 7.8, which Toptech had already distributed to customers via a July 20, 2026 advisory, ahead of the public CISA disclosure.
- It was disclosed alongside nine other TMS7/TopHAT flaws in the same bulletin, including a CVSS 10.0 unauthenticated database export bug (CVE-2026-71379) that could plausibly be chained with this one — remediate the advisory as a set.
- TMS7 and TopHAT automate fuel and bulk-liquid terminal operations at over 1,200 sites worldwide and are not on CISA's KEV catalog with no confirmed in-the-wild exploitation — but given the critical score and OT-adjacent blast radius, patch to 7.8 without waiting for evidence of active exploitation.
Sources
- NVD — CVE-2026-70356
- CISA — ICS Advisory ICSA-26-272-02: Toptech TMS7 and TopHAT
- Strix.ai — CVE-2026-70356: TMS7 Unrestricted File Upload (CVSS 9.1)
- TheHackerWire — CVE-2026-70356: TMS File Upload Vulnerability Enables Remote Code Execution
- SecurityOnline — CISA Warns of 10 Toptech TMS7 and TopHAT Vulnerabilities, One Rated CVSS 10.0
CosmicBytez Labs will update this advisory if Toptech Systems publishes additional technical detail or if active exploitation of CVE-2026-70356 is confirmed.