PT-2026-96124 · Cutenews · Cutenews

CVE-2026-36467

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CuteNews version 2.1.2
Description An unrestricted file upload issue exists in the core/modules/media.php file. Remote authenticated users with access to the Media Manager panel can upload files of dangerous types to execute arbitrary code within the web application context, which can lead to remote server access via a reverse shell.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-36467

Affected Products

Cutenews