rootpwn

high · CVSS v3 8.8 · CVSS v4 8.4

CVE-2026-5695

Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users …

Description

Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code remotely (demonstrated by uploading the EICAR test file), which could result in the system being completely compromised.

Scores

Severity
high
CVSS v2
6.5
CVSS v3
8.8
CVSS v4
8.4
EPSS

← All CVEs