Unauthenticated Arbitrary File Upload in Masteriyo Learning Management System
CVE-2026-73996
9.8CRITICAL
What is CVE-2026-73996?
The Masteriyo Learning Management System is susceptible to an unauthenticated arbitrary file upload vulnerability, which allows attackers to upload malicious files without any authentication. This weakness in versions up to 2.3.2 can potentially be exploited to execute arbitrary code or take control of the affected systems, posing significant risks to users' data and privacy. Website administrators are advised to update to the latest version and implement security measures to mitigate potential threats.
Affected Version(s)
Masteriyo - LMS <= 2.3.2