CVE-2026-93352
9.8 CRITICALpublic exploit availablePublished 2026-09-23 · Updated 2026-09-24
AI risk analysis
- Summary
- The flaw allows an attacker to upload a .pht file, which is executed as PHP, leading to remote code execution.
- Exploitability
- Exploitation is relatively easy if the attacker can upload a file to the server, as the .pht extension is not blocked by the configuration.
- Blast radius
- If exploited, the impact could be severe, as it allows remote code execution with the privileges of the web server process.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Laravel-Mediable 7.0.2 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .pht file that passes all validation in MediaUploader::verifyExtension() and File::sanitizeFileName() because pht is not present in the blocklist, causing the file to be written to disk and executed as PHP when requested, enabling remote code execution with the privileges of the web server process.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-70356PoC
- CRITICALCVE-2026-82187
- HIGHCVE-2026-94104PoC
- HIGHCVE-2026-12264
- CRITICALCVE-2026-14175
- HIGHCVE-2026-14553
- CRITICALCVE-2026-16618
- CRITICALCVE-2026-18143
Related by shared AI tags and CWE weakness class. Browse the full archive.