Unrestricted Upload Vulnerability in Diem-Project Diem Widget Editor
CVE-2026-82679
Key Information:
- Vendor
Diem-project
- Status
- Vendor
- CVE Published:
- 31 August 2026
Badges
What is CVE-2026-82679?
A security flaw exists in the Diem Widget Editor component, specifically in the dmWidgetContentBaseMediaForm.php file. This vulnerability allows an attacker to manipulate the system and perform unrestricted file uploads, which can be initiated remotely. This poses a significant risk for unauthorized access and potential system compromise. Despite early notification regarding the issue, the project has not taken responsive action, leaving the vulnerability unaddressed.
Affected Version(s)
diem 5.1.0
diem 5.1.1
diem 5.1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
