CVE-2026-14946

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-20 09:16

Updated : 2026-09-03 16:57


NVD link : CVE-2026-14946

Mitre link : CVE-2026-14946

CVE.ORG link : CVE-2026-14946


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type