← Back to search

CVE-2026-88419

8.8 HIGHpublic exploit available

Published 2026-09-22 · Updated 2026-09-24

AI risk analysis

Summary
The flaw allows an authenticated low-privileged user to upload a .php file, leading to arbitrary code execution on the server due to lack of proper file extension validation and content checks.
Exploitability
Exploitation is relatively straightforward given the lack of validation, and requires an authenticated user with low privileges.
Blast radius
If exploited, the impact is high as it can lead to full server compromise and arbitrary code execution.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to WuzhiCMS 5.0.1 or later.
rceauth-bypassweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrary PHP code on the server, because the stored file extension is taken verbatim from the client-supplied filename with no extension allowlist or content validation and the file is written to the web-accessible uploadfile/ directory, from which the web server executes PHP.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.