OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-104890: Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution

GitHub Advisories · officialPublished Oct 7, 2026Risk 37/100

### Summary The MediaBundle blocks dangerous upload extensions with a blacklist that was matched case-sensitively, while the stored filename was lowercased afterwards. A file uploaded as `webshell.pHp` therefore bypassed the blacklist and was written to the web-accessible upload directory as `webshell.php`, where the web server executed it. Any authenticated backend user with access to the media section could obtain remote code execution. ### Details `FileHandler::getFilePath()` rewrote blacklisted extensions to `.txt` using a case-sensitive regex, and only then lowercased the extension when building the stored name — so the check ran against the attacker-controlled casing and the normalisation happened after it. Two further weaknesses contributed: * The default blacklist contained only `php` and `htaccess`, leaving other server-executable extensions (`phtml`, `php5`, `phar`, `shtml`, `cgi`, …) unblocked regardless of casing. * Configured blacklist values were interpolated into the regex unescaped. ### Impact An authenticated user with access to the admin media section can upload a file that the web server executes as PHP. The uploaded file is reachable over HTTP without authentication, giving arbitrary code execution as the web server user. ### Patches Fixed in kunstmaan/media-bundle 7.3.2. The extension is now normalised before it is checked and compared with `in_array()`; the default blacklist is expanded to the full set of server-executable extensions; and a new opt-in `allowed_extensions` option allows projects to enforce a strict allow-list. Note that the patch does not rename files already stored on disk. Sites should audit their media upload directory for existing files with an executable extension. ### Workarounds If you cannot upgrade, configure the web server to refuse to execute scripts in the media upload directory (for example a `location` block in nginx or `php_flag engine off` in Apache).

Upgrade affected packages to a patched version: kunstmaan/media-bundle 7.3.2, kunstmaan/bundles-cms 7.3.2.

Vendor
Not specified
Product
kunstmaan/media-bundle, kunstmaan/bundles-cms
Exploitation
none known
Evidence
official
CVSS
7.2

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source