← Back to search

CVE-2026-36467

7.2 HIGHpublic exploit available

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
This vulnerability allows remote authenticated users to execute arbitrary code by uploading a file with a dangerous type, leading to potential remote server access.
Exploitability
Exploitation requires access to the Media Manager panel and is moderately difficult due to authentication requirements but straightforward once gained.
Blast radius
If exploited, this can result in full control over the affected web application’s server environment, impacting all users and data.
Prioritized remediation
Update to a patched version of CuteNews or apply a security patch if available.
rcewebauth-bypasscode-execution

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.