CVE-2026-2560: kalcaddle kodbox Media File Preview Plugin VideoResize.class.php run os command injection
A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoResize.class.php of the component Media File Preview Plugin. Such manipulation of the argument localFile leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2560?
CVE-2026-2560 has a high severity due to its potential for OS command injection.
How do I fix CVE-2026-2560?
To fix CVE-2026-2560, update kalcaddle kodbox to a version later than 1.64.05.
What components are affected by CVE-2026-2560?
CVE-2026-2560 affects the Media File Preview Plugin in kalcaddle kodbox.
Can CVE-2026-2560 lead to remote code execution?
Yes, CVE-2026-2560 can lead to remote code execution through OS command injection.
What versions of kalcaddle kodbox are vulnerable to CVE-2026-2560?
All versions of kalcaddle kodbox up to and including 1.64.05 are vulnerable to CVE-2026-2560.