Security1 publisher2 min readPublished
Toptech TMS7 and TopHAT 7.6.3 let unauthenticated attackers export any database table
CISA says Toptech TMS7 and TopHAT 7.6.3 carry ten CVEs, one of which lets unauthenticated attackers export any database table they choose. Toptech told customers on July 20 that release 7.8 fixes them, so the sites at risk are those still on 7.6.3.
The Watch · Security desk

What happened
- The TMS upload endpoint does not check file types on the server side, so an attacker can upload a PHP file to the web server and execute it.
- Time-based blind SQL injection sits in several parameters, including supplier_no in business allocation search and screenID in the electronic transaction queue viewer.
- TMS7 and TopHAT carry the same CVE list, so a site running either product on 7.6.3 has the full set.
- CISA lists the products as deployed worldwide in the energy, chemical and transportation systems sectors, from a vendor based in the United States.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure On 7.6.3, the one condition an attacker must meet to pull database tables is network reach to the web interface.
- capability The PHP upload flaw takes an attacker past data theft to running their own code on a web server at energy, chemical or transportation sites.
- decision The only remedy listed is a full release upgrade to 7.8. Sites that cannot schedule that soon have to decide how they will restrict access to the web interface in the meantime.
The export endpoint is the flaw to close first. One crafted POST request, sent without logging in, returns whichever database tables the attacker asks for [3]. CISA classes it as CWE-552, files or directories accessible to external parties [4].
CISA's summary covers both outcomes the flaws allow. Exploitation "could allow an attacker to access critical data or execute arbitrary code," the agency wrote [1]. The export endpoint gets an attacker the first without credentials [3]. The PHP upload flaw gets them the second. CISA files it under CWE-434, unrestricted upload of file with dangerous type [5].
I think the SQL injections matter least of the flaws described, at least for an attacker who wants data. They are time-based blind injections, filed as CWE-89 [6]. The export endpoint is a faster route to the same goal. It needs no login and returns full tables [3].
The advisory does not say whether the upload and injection flaws require an authenticated session, or whether any of the ten has been exploited [5][6].
Every flaw in the advisory has the same remedy, release 7.8. Toptech directs customers to its security blog for the release and details [8]. The vendor's own notice to customers went out on July 20, 2026 [7].
The ten identifiers are CVE-2026-63713, CVE-2026-68068, CVE-2026-68954, CVE-2026-69662, CVE-2026-70356, CVE-2026-71189, CVE-2026-71302, CVE-2026-71379, CVE-2026-72507 and CVE-2026-72510 [2][1].
What to watch
- A report of exploitation against the unauthenticated export endpoint would move 7.6.3 sites from upgrade planning to incident response.
- If Toptech or CISA confirms the PHP upload endpoint also works without a login, 7.6.3 has unauthenticated code execution.
- Public proof-of-concept code for any of the ten CVEs.