OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-5695

HIGH · CVSS 8.4 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

An arbitrary file upload vulnerability exists due to insufficient validation in upload forms, allowing authenticated users to upload files without restrictions. This flaw can be exploited by attackers to execute malicious code remotely, potentially leading to complete system compromise. Organizations with web applications that allow file uploads should prioritize addressing this vulnerability to mitigate the risk of unauthorized access and data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-5695
Severity
HIGH
CVSS
8.4
EPSS
0.30%

Original NVD Description

Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code remotely (demonstrated by uploading the EICAR test file), which could result in the system being completely compromised.