Arbitrary File Upload Vulnerability in Microweber by Microweber
CVE-2026-5695
8.4HIGH
What is CVE-2026-5695?
An arbitrary file upload vulnerability exists in Microweber due to inadequate validation of upload forms. Authenticated users may exploit this flaw to upload files to the server unrestrictedly, enabling the execution of malicious code. Such exploitation can compromise system integrity, exemplified by the ability to upload harmful files, like the EICAR test file, illustrating the risk of remote code execution and unauthorized access.
Affected Version(s)
Administration panel 2.0.19
