CVE-2026-34413: Xerte Online Toolkits Missing Authentication via connector.php

Published Apr 22, 2026
·
Updated

Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unauthenticated callers does not call exit() or die(), allowing PHP execution to continue and process the full request server-side. Unauthenticated attackers can perform file operations on project media directories including creating directories, uploading files, renaming files, duplicating files, overwriting files, and deleting files, which can be chained with path traversal and extension blocklist vulnerabilities to achieve remote code execution and arbitrary file read.

Affected Software

1 affected component
Xerte Xerte Online Toolkits<=3.15

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Xerte Online Toolkits to a version that resolves this vulnerability.

    Fixed in 3.15
  2. Configuration

    In /editor/elfinder/php/connector.php at the elFinder connector endpoint, modify the missing-authentication branch so that after redirecting unauthenticated callers, execution is terminated (use exit() or die()), preventing further server-side request processing.

    Xerte Online Toolkits (editor/elfinder/php/connector.php) Missing authentication handling (HTTP redirect to unauthenticated callers must terminate execution) = Ensure the redirect path calls exit() or die() so PHP execution does not continue after redirect.

Event History

Apr 22, 2026
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-34413?

CVE-2026-34413 has a medium severity level due to its ability to allow unauthenticated access.

2

How do I fix CVE-2026-34413?

To fix CVE-2026-34413, update Xerte Online Toolkits to version 3.16 or later, where the vulnerability has been addressed.

3

What specific component is impacted by CVE-2026-34413?

CVE-2026-34413 specifically impacts the elFinder connector endpoint located at /editor/elfinder/php/connector.php.

4

Who is affected by CVE-2026-34413?

Users of Xerte Online Toolkits versions 3.15 and earlier are affected by CVE-2026-34413.

5

What could an attacker achieve with CVE-2026-34413?

An attacker could exploit CVE-2026-34413 to gain unauthorized access to resources through the vulnerable endpoint.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203