Remote Code Execution Vulnerability in vsDesk Product by vsDesk
CVE-2026-2334

9.4CRITICAL

Key Information:

Vendor

Vsdesk

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-2334?

An issue in vsDesk v14.0101 allows authenticated attackers with administrative privileges to bypass client-side file validation due to insufficient server-side checks in the 'Import via CSV' component. This vulnerability enables the upload of arbitrary files, potentially resulting in Remote Code Execution (RCE) within the web application environment. To mitigate this risk, users are advised to apply the latest patch available in versions 14.0402 and onwards.

Affected Version(s)

vsDesk 14.0101

vsDesk 14.0402

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The vulnerability was discovered by Kirill Nikolaev from Kaspersky (https://kaspersky.com)
.