Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

CVE-2026-104890: CVE-2026-104890: Remote Code Execution via Mixed-Case File Upload Bypass in Kunstmaan CMS MediaBundle

CVE-2026-104890: Remote Code Execution via Mixed-Case File Upload Bypass in Kunstmaan CMS MediaBundle Vulnerability ID: CVE-2026-104890 CVSS Score: 7.2 Published: 2026-10-07 Kunstmaan CMS MediaBundle prior to versio

CVE-2026-104890: Remote Code Execution via Mixed-Case File Upload Bypass in Kunstmaan CMS MediaBundle

Vulnerability ID: CVE-2026-104890
CVSS Score: 7.2
Published: 2026-10-07

Kunstmaan CMS MediaBundle prior to version 7.3.2 contains a critical file upload vulnerability where case-sensitive extension checks can be bypassed using mixed-case file extensions. Because extension normalization occurs after the validation routine, files with mixed-case executable extensions (such as pHp) bypass checks but are stored with normalized lowercase executable extensions, allowing authenticated administrators to achieve remote code execution.

TL;DR

An authenticated administrator can bypass file upload restrictions by uploading mixed-case extensions (e.g., .pHp), which are subsequently normalized to .php and stored on the filesystem, enabling remote code execution.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-434
  • Attack Vector: Network (AV:N)
  • Attack Complexity: Low (AC:L)
  • Privileges Required: High (PR:H)
  • CVSS Score: 7.2 (High)
  • Exploit Status: PoC Available
  • EPSS Score: 0.00416 (0.42%)

Affected Systems

  • Kunstmaan CMS MediaBundle
  • MediaBundle: < 7.3.2 (Fixed in: 7.3.2)

Mitigation Strategies

  • Upgrade to Kunstmaan CMS 7.3.2 or higher to apply corrected filename sanitization
  • Implement strict file upload whitelisting by defining allowed extensions
  • Disable engine execution within the public upload folder on the web server

Remediation Steps:

  1. Update composer dependencies: Run 'composer update' to upgrade the 'kunstmaan/bundles-cms' package to version 7.3.2 or above.
  2. Audit existing uploaded files: Inspect the web-accessible media directories for any files containing executable headers or mixed-case extensions.
  3. Configure web server execution restrictions: Apply rules in Nginx or Apache config files to deny script interpreter invocation inside the public uploads folder.
  4. Apply strict application whitelisting: Implement the 'allowed_extensions' parameter in 'config/packages/kunstmaan_media.yaml'.

Read the full report for CVE-2026-104890 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.