CVE-2026-104890: Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution
### Summary The MediaBundle blocks dangerous upload extensions with a blacklist that was matched case-sensitively, while the stored filename was lowercased afterwards. A file uploaded as `webshell.pHp` therefore bypassed the blacklist and was written to the web-accessible upload directory as `webshell.php`, where the web server executed it. Any authenticated backend user with access to the media section could obtain remote code execution. ### Details `FileHandler::getFilePath()` rewrote blacklisted extensions to `.txt` using a case-sensitive regex, and only then lowercased the extension when building the stored name — so the check ran against the attacker-controlled casing and the normalisation happened after it. Two further weaknesses contributed: * The default blacklist contained only `php` and `htaccess`, leaving other server-executable extensions (`phtml`, `php5`, `phar`, `shtml`, `cgi`, …) unblocked regardless of casing. * Configured blacklist values were interpolated into the regex unescaped. ### Impact An authenticated user with access to the admin media section can upload a file that the web server executes as PHP. The uploaded file is reachable over HTTP without authentication, giving arbitrary code execution as the web server user. ### Patches Fixed in kunstmaan/media-bundle 7.3.2. The extension is now normalised before it is checked and compared with `in_array()`; the default blacklist is expanded to the full set of server-executable extensions; and a new opt-in `allowed_extensions` option allows projects to enforce a strict allow-list. Note that the patch does not rename files already stored on disk. Sites should audit their media upload directory for existing files with an executable extension. ### Workarounds If you cannot upgrade, configure the web server to refuse to execute scripts in the media upload directory (for example a `location` block in nginx or `php_flag engine off` in Apache).
Recommended action
Recommended action
Upgrade affected packages to a patched version: kunstmaan/media-bundle 7.3.2, kunstmaan/bundles-cms 7.3.2.
Technical details
- Vendor
- Not specified
- Product
- kunstmaan/media-bundle, kunstmaan/bundles-cms
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source