CVE-2026-104890
Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution
Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklisted_extensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An authenticated backend user with media access can upload a mixed-case executable extension such as PHP that bypasses the check and is stored in the web-accessible media directory with an executable lowercase extension. The default blacklist also omits several server-executable extension types, allowing the same code-execution impact where the web server executes uploaded files. This issue is fixed in version 7.3.2.
| CWE | CWE-434 |
| Vendor | kunstmaan |
| Product | kunstmaanbundlescms |
| Published | Oct 5, 2026 |
Get instant alerts for kunstmaan kunstmaanbundlescms
Be the first to know when new high vulnerabilities affecting kunstmaan kunstmaanbundlescms are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H