OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-94123

HIGH · CVSS 7.5 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

NextGEN Gallery versions up to 4.5.0 are vulnerable to an unauthenticated arbitrary file download, allowing attackers to exploit this flaw to access sensitive files on the server. This high-severity vulnerability poses a significant risk to web applications using the affected plugin, particularly those handling sensitive data or user uploads. Organizations utilizing NextGEN Gallery should prioritize immediate patching or mitigation strategies to safeguard against potential data breaches.

CVE
CVE-2026-94123
Severity
HIGH
CVSS
7.5
EPSS
0.40%

Original NVD Description

Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.