← Back to search

CVE-2026-93352

9.8 CRITICALpublic exploit available

Published 2026-09-23 · Updated 2026-09-24

AI risk analysis

Summary
The flaw allows an attacker to upload a .pht file, which is executed as PHP, leading to remote code execution.
Exploitability
Exploitation is relatively easy if the attacker can upload a file to the server, as the .pht extension is not blocked by the configuration.
Blast radius
If exploited, the impact could be severe, as it allows remote code execution with the privileges of the web server process.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Laravel-Mediable 7.0.2 or later.
rcewebphpupload

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .pht file that passes all validation in MediaUploader::verifyExtension() and File::sanitizeFileName() because pht is not present in the blocklist, causing the file to be written to disk and executed as PHP when requested, enabling remote code execution with the privileges of the web server process.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.