← Back to CVE search

CVE-2026-64881

Unknown

Description

The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.

CVSS 8.8EPSS 1.44%Risk 0.99
View source
Published
2026-07-21 21:16:53
Affected versions
unknown
Type
Other
Last modified
2026-07-24 05:16:48
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H