CVE-2026-32985: Xerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code Execution
Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality that allows remote attackers to execute arbitrary code by uploading a crafted ZIP archive containing malicious PHP payloads. Attackers can bypass authentication checks in the import.php file to upload a template archive with PHP code in the media directory, which gets extracted to a web-accessible path where the malicious PHP can be directly accessed and executed under the web server context.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Xerte Online Toolkitsto a version that resolves this vulnerability.Fixed in 3.14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32985?
CVE-2026-32985 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-32985?
To mitigate CVE-2026-32985, upgrade Xerte Online Toolkits to version 3.15 or later to close the unauthorized file upload vulnerability.
What are the risks of CVE-2026-32985?
CVE-2026-32985 allows unauthenticated users to upload arbitrary files, potentially leading to remote code execution and full system compromise.
Who is affected by CVE-2026-32985?
All users running Xerte Online Toolkits version 3.14 and earlier are affected by CVE-2026-32985.
What are the symptoms of exploitation of CVE-2026-32985?
Exploitation of CVE-2026-32985 may lead to unauthorized access, system instability, or unusual application behavior indicative of remote code execution.