CVE-2023-34854: Malicious File Upload
Published Sep 14, 2026
·Updated
Authenticated remote code execution via backup/restore in HotelDruid
Other sources
HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
— MITRE
Affected Software
2 affected componentsFixes available
HotelDruid<3.0.6
debian/hoteldruid<=3.0.4-1
3.0.8-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/hoteldruidto a version that resolves this vulnerability.Fixed in 3.0.8-1
Event History
Sep 14, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via Debian·05:16 AM
DescriptionAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs authenticated access with high privileges. The attack can be performed remotely and does not require user interaction, but the attack complexity is high.
2
Which deployments are affected?
HotelDruid versions before 3.0.6 are affected, including the listed Debian hoteldruid package. The issue is in the backup/restore function.
3
What is the impact if exploitation succeeds?
Successful exploitation can result in remote code execution with high impact to confidentiality, integrity, and availability.