ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. Attackers can initialize chunked uploads, send file parts, and complete uploads to leave arbitrary files in the storage backend accessible via web server URLs.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-25 19:16
Updated : 2026-08-26 14:17
NVD link : CVE-2026-80050
Mitre link : CVE-2026-80050
CVE.ORG link : CVE-2026-80050
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
