Unauthenticated File Upload Vulnerability in Feng Office by Feng Office
CVE-2026-36669
9.8CRITICAL
What is CVE-2026-36669?
Feng Office version 3.11.13.11 is vulnerable to an unauthenticated arbitrary file upload through the ck_upload_handler.php script. This vulnerability allows remote attackers to upload malicious files, such as HTML scripts, to the publicly accessible /tmp/ directory. Successful exploitation of this vulnerability can lead to unauthorized commands being executed on the server, potentially compromising the entire website and exposing sensitive data.
