PT-2026-105994 · Undefined · Undefined

CVE-2026-104826

·

Published

2026-10-05

·

Updated

2026-10-05

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
DropzoneFileExplorer chunked upload trusts fileName all the way to fopen()!!
CVE-2026-104826 (CVSS 8.5). v1.1. Traversal walks out of the storage root into the web root. PHP runs. Auth required unless AUTH ENABLE=false.
CVE assigned 2 Oct. Fixed in v1.2. PoC dropped 3 Oct!!
#Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #RCE #FileUpload
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-104826

Affected Products

Undefined