PT-2026-78366 · Zoo · Zoo

CVE-2026-74803

·

Published

2026-08-19

·

Updated

2026-08-20

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Zoo versions prior to 4.1.64
Description An unauthenticated arbitrary file upload issue exists in the image element. The system accepts arbitrary files as long as the client-supplied Content-Type falls within the image MIME group (Multipurpose Internet Mail Extensions, a standard that indicates the nature and format of a document).
Recommendations Update Zoo to version 4.1.64 or later.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74803

Affected Products

Zoo