CVE-2026-36467
7.2 HIGHpublic exploit availablePublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- This vulnerability allows remote authenticated users to execute arbitrary code by uploading a file with a dangerous type, leading to potential remote server access.
- Exploitability
- Exploitation requires access to the Media Manager panel and is moderately difficult due to authentication requirements but straightforward once gained.
- Blast radius
- If exploited, this can result in full control over the affected web application’s server environment, impacting all users and data.
- Prioritized remediation
- Update to a patched version of CuteNews or apply a security patch if available.
rcewebauth-bypasscode-execution
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-14553
- HIGHCVE-2026-6147
- HIGHCVE-2026-15979
- CRITICALCVE-2026-16940
- MEDIUMCVE-2026-46650PoC
- HIGHCVE-2026-55159PoC
- HIGHCVE-2026-55897PoC
- HIGHCVE-2026-59814PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.