CVE-2026-104890

Source
https://cve.org/CVERecord?id=CVE-2026-104890
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104890.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-104890
Aliases
Published
2026-10-05T15:46:21Z
Modified
2026-10-07T02:47:26Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution
Details

Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklisted_extensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An authenticated backend user with media access can upload a mixed-case executable extension such as PHP that bypasses the check and is stored in the web-accessible media directory with an executable lowercase extension. The default blacklist also omits several server-executable extension types, allowing the same code-execution impact where the web server executes uploaded files. This issue is fixed in version 7.3.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-434"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104890.json"
}
References

Affected packages

Git / github.com/kunstmaan/kunstmaanbundlescms

Affected ranges

Type
GIT
Repo
https://github.com/kunstmaan/kunstmaanbundlescms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "7.3.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

3.*
3.0.0
3.0.1
3.0.2
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.1.1
3.2.2
3.2.3
3.2.4
3.2.4.1
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
4.*
4.0.0
4.0.0-RC1
5.*
5.0.0
5.0.0-RC1
5.0.0-RC2
5.0.1
5.0.2
5.1.0
5.2.0
5.3.0
7.*
7.1.0-alpha1
7.3.0
7.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104890.json"