PT-2026-84294 · Fs Poster · Fs Poster

·

CVE-2026-10195

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FS-Poster versions prior to 8.0.2
Description Insufficient input sanitization of the FFmpeg path parameter before it is passed to the exec() function, combined with missing authorization checks on REST API endpoints, allows authenticated attackers with subscriber-level access or higher to execute arbitrary commands on the server. Remote Code Execution refers to the ability of an attacker to run any command of their choice on a target machine.
Recommendations Update FS-Poster to a version newer than 8.0.1. Restrict access to the REST API endpoints used for FFmpeg path configuration to minimize the risk of exploitation.

Fix

RCE

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10195

Affected Products

Fs Poster