File Upload Vulnerability in Kunstmaan CMS by Kunstmaan
CVE-2026-104890
What is CVE-2026-104890?
Kunstmaan CMS, an open-source content management system based on the Symfony framework, has a file upload vulnerability that allows authenticated backend users to upload files with mixed-case executable extensions, like .PHP. The vulnerability arises because the system performs a case-sensitive check against blacklisted file extensions when uploading files, allowing it to bypass these checks. Additionally, the default configuration generates files that can be stored in web-accessible directories, potentially leading to arbitrary code execution when the compromised files are executed by the web server. This serious issue has been addressed in version 7.3.2, emphasizing the importance of updating to mitigate the risks associated with unauthorized file uploads.
Affected Version(s)
bundles-cms < 7.3.1
KunstmaanBundlesCMS < 7.3.1
media-bundle < 7.3.1
