← Retour à la recherche de CVE

CVE-2026-64881

Unknown

Description

The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.

CVSS 8.8EPSS 1.44%Risque 0.99
Voir la source
Publication
2026-07-21 21:16:53
Versions concernées
unknown
Type
Autre
Dernière modification
2026-07-24 05:16:48
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H