CVE-2026-36467: CuteNews CuteNews vulnerability
Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Remote authenticated users who have access to the Media Manager panel can exploit it. The issue is not described as reachable by unauthenticated users.
What level of access does successful exploitation provide?
An attacker can execute arbitrary code in the context of the web application. This can lead to remote access to the affected server, including through a triggered reverse shell.
What capability does an attacker need before exploitation?
The attacker needs valid authenticated access and permission to use the Media Manager panel. The provided information does not state whether such access is granted to any default user role.