Remote Code Execution Vulnerability in Bludit CMS by Bludit
CVE-2026-38329
9.8CRITICAL
What is CVE-2026-38329?
A vulnerability exists in Bludit CMS versions prior to 3.18.4 that allows attackers to execute arbitrary code on the server. This flaw arises from improper authorization checks and the lack of file extension validation in the API Plugin. Specifically, the POST /api/files/{key} endpoint can be exploited by an attacker possessing a valid API token, enabling them to upload a malicious PHP script. This oversight presents a significant security risk, compromising the integrity of the server and potentially leading to unauthorized access.
