๐Ÿ” CVE Alert

CVE-2026-104890

HIGH 7.2

Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklisted_extensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An authenticated backend user with media access can upload a mixed-case executable extension such as PHP that bypasses the check and is stored in the web-accessible media directory with an executable lowercase extension. The default blacklist also omits several server-executable extension types, allowing the same code-execution impact where the web server executes uploaded files. This issue is fixed in version 7.3.2.

CWE CWE-434
Vendor kunstmaan
Product kunstmaanbundlescms
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for kunstmaan kunstmaanbundlescms

Be the first to know when new high vulnerabilities affecting kunstmaan kunstmaanbundlescms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Kunstmaan / KunstmaanBundlesCMS
< 7.3.1
kunstmaan / bundles-cms
< 7.3.1
kunstmaan / media-bundle
< 7.3.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Kunstmaan/KunstmaanBundlesCMS/security/advisories/GHSA-p279-5wcv-45vq github.com: https://github.com/Kunstmaan/KunstmaanBundlesCMS/commit/1bbdfdeac8e7e91506b1a9271360b9b68d7690d3 github.com: https://github.com/Kunstmaan/KunstmaanBundlesCMS/releases/tag/7.3.2