A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.
References
| Link | Resource |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-078/ |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-20 09:16
Updated : 2026-09-03 16:57
NVD link : CVE-2026-14946
Mitre link : CVE-2026-14946
CVE.ORG link : CVE-2026-14946
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
