CVE-2026-104890: CVE-2026-104890: Remote Code Execution via Mixed-Case File Upload Bypass in Kunstmaan CMS MediaBundle
CVE-2026-104890: Remote Code Execution via Mixed-Case File Upload Bypass in Kunstmaan CMS MediaBundle Vulnerability ID: CVE-2026-104890 CVSS Score: 7.2 Published: 2026-10-07 Kunstmaan CMS MediaBundle prior to versio
CVE-2026-104890: Remote Code Execution via Mixed-Case File Upload Bypass in Kunstmaan CMS MediaBundle
Vulnerability ID: CVE-2026-104890
CVSS Score: 7.2
Published: 2026-10-07
Kunstmaan CMS MediaBundle prior to version 7.3.2 contains a critical file upload vulnerability where case-sensitive extension checks can be bypassed using mixed-case file extensions. Because extension normalization occurs after the validation routine, files with mixed-case executable extensions (such as pHp) bypass checks but are stored with normalized lowercase executable extensions, allowing authenticated administrators to achieve remote code execution.
TL;DR
An authenticated administrator can bypass file upload restrictions by uploading mixed-case extensions (e.g., .pHp), which are subsequently normalized to .php and stored on the filesystem, enabling remote code execution.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-434
- Attack Vector: Network (AV:N)
- Attack Complexity: Low (AC:L)
- Privileges Required: High (PR:H)
- CVSS Score: 7.2 (High)
- Exploit Status: PoC Available
- EPSS Score: 0.00416 (0.42%)
Affected Systems
- Kunstmaan CMS MediaBundle
-
MediaBundle: < 7.3.2 (Fixed in:
7.3.2)
Mitigation Strategies
- Upgrade to Kunstmaan CMS 7.3.2 or higher to apply corrected filename sanitization
- Implement strict file upload whitelisting by defining allowed extensions
- Disable engine execution within the public upload folder on the web server
Remediation Steps:
- Update composer dependencies: Run 'composer update' to upgrade the 'kunstmaan/bundles-cms' package to version 7.3.2 or above.
- Audit existing uploaded files: Inspect the web-accessible media directories for any files containing executable headers or mixed-case extensions.
- Configure web server execution restrictions: Apply rules in Nginx or Apache config files to deny script interpreter invocation inside the public uploads folder.
- Apply strict application whitelisting: Implement the 'allowed_extensions' parameter in 'config/packages/kunstmaan_media.yaml'.
Read the full report for CVE-2026-104890 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.