OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-36467

HIGH · CVSS 7.2 EPSS 0.53% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

CuteNews v2.1.2 is vulnerable to an unrestricted file upload flaw in the media.php module, allowing authenticated users with Media Manager access to upload malicious files. This could enable attackers to execute arbitrary code, potentially gaining remote server access through a reverse shell. Organizations using this version should prioritize patching to mitigate the risk of unauthorized access and potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-36467
Severity
HIGH
CVSS
7.2
EPSS
0.53%

Original NVD Description

Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.