PT-2026-105994 · Undefined · Undefined
CVE-2026-104826
·
Published
2026-10-05
·
Updated
2026-10-05
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
DropzoneFileExplorer chunked upload trusts fileName all the way to fopen()!!
CVE-2026-104826 (CVSS 8.5). v1.1. Traversal walks out of the storage root into the web root. PHP runs. Auth required unless AUTH ENABLE=false.
CVE assigned 2 Oct. Fixed in v1.2. PoC dropped 3 Oct!!
#Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #RCE #FileUpload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined