SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64879

CRITICAL · CVSS 9.9 EPSS 2.59%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The vulnerability arises from improper sanitization of filenames during file uploads, enabling attackers to inject shell metacharacters and execute arbitrary commands on the system. This critical flaw poses a significant risk to any application utilizing the affected file upload functionality, potentially leading to unauthorized access or system compromise. Organizations that implement file upload features should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-64879
Severity
CRITICAL
CVSS
9.9
EPSS
2.59%

Original NVD Description

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

Related CVEs

Other vulnerabilities affecting the same vendor(s)