๐Ÿ” CVE Alert

CVE-2026-53599

HIGH 7.5

Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polyglot named shell.php.any.jpg, which web servers with multi-extension PHP handlers can execute as the web-server user. This issue is fixed in version 5.21.1.

CWE CWE-434
Vendor redaxo
Product core
Published Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for redaxo core

Be the first to know when new high vulnerabilities affecting redaxo core are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

redaxo / core
>= 5.18.2, < 5.21.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/redaxo/core/security/advisories/GHSA-98pp-vccm-qm25 github.com: https://github.com/redaxo/core/pull/6538 github.com: https://github.com/redaxo/core/commit/462e36896bb65d292ba22d711044c23c9cfb0340 github.com: https://github.com/redaxo/core/releases/tag/5.21.1