SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-49849

CRITICAL · CVSS 9.1 EPSS 0.93% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows authenticated administrators to upload malicious executable files, potentially leading to Remote Code Execution (RCE) and full system compromise. Organizations using this version should prioritize patching to version 3.0.4 to mitigate the critical risk associated with this vulnerability. Immediate action is essential for any entity relying on xShop for their operations.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-49849
Severity
CRITICAL
CVSS
9.1
EPSS
0.93%

Original NVD Description

xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By uploading a specially crafted php file, an attacker can achieve Remote Code Execution (RCE) on the server, leading to a full system compromise. Version 3.0.4 fixes the issue.