File Upload Vulnerability in Kunstmaan CMS by Kunstmaan
CVE-2026-104890

7.2HIGH

Key Information:

Vendor

Kunstmaan

Vendor
CVE Published:
5 October 2026

What is CVE-2026-104890?

Kunstmaan CMS, an open-source content management system based on the Symfony framework, has a file upload vulnerability that allows authenticated backend users to upload files with mixed-case executable extensions, like .PHP. The vulnerability arises because the system performs a case-sensitive check against blacklisted file extensions when uploading files, allowing it to bypass these checks. Additionally, the default configuration generates files that can be stored in web-accessible directories, potentially leading to arbitrary code execution when the compromised files are executed by the web server. This serious issue has been addressed in version 7.3.2, emphasizing the importance of updating to mitigate the risks associated with unauthorized file uploads.

Affected Version(s)

bundles-cms < 7.3.1

KunstmaanBundlesCMS < 7.3.1

media-bundle < 7.3.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.