CVE-2026-78839: AppNitro MachForm vulnerability
Published Sep 4, 2026
·Updated
An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading a crafted .phar file.
Affected Software
1 affected component
AppNitro MachForm=30
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker needs the ability to upload a crafted .phar file through a vulnerable MachForm v30 file-upload path. Successful exploitation can result in arbitrary code execution.
2
How can I determine whether my deployment is affected?
Check whether the deployment is running AppNitro MachForm v30 and exposes functionality that permits file uploads. The provided information specifically identifies crafted .phar uploads as the attack vector.