SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-2334

CRITICAL · CVSS 9.4 EPSS 0.52% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An authenticated attacker with administrative privileges in vsDesk v14.0101 can exploit a lack of server-side validation in the "Import via CSV" component to bypass client-side file validation, enabling the upload of arbitrary files. This vulnerability can lead to Remote Code Execution (RCE) within the web application, posing a critical risk to affected systems. Organizations using this version should prioritize applying the vendor's patch, as versions 14.0402 and later contain the fix.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-2334
Severity
CRITICAL
CVSS
9.4
EPSS
0.52%

Original NVD Description

An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution (RCE) within the context of the web application.  Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.