CVE-2026-25099 - Remote Code Execution via Unrestricted File Upload in Bludit
CVE ID :CVE-2026-25099
Published : March 27, 2026, 12:16 p.m. | 48 minutes ago
Description :Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 27, 2026, 12:16 p.m. | 48 minutes ago
Description :Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...