OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104890

HIGH · CVSS 7.2 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Kunstmaan CMS versions prior to 7.3.2 are vulnerable to a file upload issue that allows authenticated backend users to bypass the extension blacklist by uploading files with mixed-case executable extensions, such as PHP. This can lead to arbitrary code execution if the web server processes these files, posing a significant risk to the integrity and security of the application. Organizations using Kunstmaan CMS should prioritize updating to version 7.3.2 or later to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104890
Severity
HIGH
CVSS
7.2
EPSS
0.42%

Original NVD Description

Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklisted_extensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An authenticated backend user with media access can upload a mixed-case executable extension such as PHP that bypasses the check and is stored in the web-accessible media directory with an executable lowercase extension. The default blacklist also omits several server-executable extension types, allowing the same code-execution impact where the web server executes uploaded files. This issue is fixed in version 7.3.2.