Remote Code Execution in HortusFox by Daniel Brendel
CVE-2026-104069

8.6HIGH

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-104069?

HortusFox before version 6.2 has a significant vulnerability in the ThemeModule::startImport() function. This flaw allows an authenticated administrator to upload a specially crafted ZIP archive that contains malicious PHP code and an .htaccess file. The lack of validation on the file names, extensions, and content when extracting the archive directly into the public web root can lead to unauthorized execution of arbitrary OS commands as the web server user. This vulnerability highlights the critical need for rigorous file validation protocols in any application dealing with file uploads.

Affected Version(s)

hortusfox-web 0 < 6.2

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Młynarczyk
VulnCheck
.