OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-5695 (CVSS 8.4)

NVD · officialPublished Sep 23, 2026Risk 37/100EPSS 0.3%

Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code remotely (demonstrated by uploading the EICAR test file), which could result in the system being completely compromised.

CVSS
8.4
AV:NetworkAC:LowPR:HighUI:Active

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source