The flaw allows remote code execution via a public REST API, giving attackers a direct path to compromise enterprise ...