Description
Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklisted_extensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An authenticated backend user with media access can upload a mixed-case executable extension such as PHP that bypasses the check and is stored in the web-accessible media directory with an executable lowercase extension. The default blacklist also omits several server-executable extension types, allowing the same code-execution impact where the web server executes uploaded files. This issue is fixed in version 7.3.2.
Published: 2026-10-05
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Kunstmaan CMS allowed authenticated administrators to upload media files that bypassed the blacklist of disallowed extensions. Because the check for denied extensions was case‑sensitive and the stored filename was lower‑cased after upload, a mixed‑case executable extension such as "php" could be uploaded and stored in the web‑accessible media directory. The default blacklist also omitted several server‑executable types, so an uploaded executable could be executed directly by the web server. This flaw is a classic example of improper file type validation (CWE‑434), giving an attacker the ability to run arbitrary code on the host. The impact is full remote code execution on the system running the CMS.

Affected Systems

The vulnerability affects the Kunstmaan CMS ecosystem, including KunstmaanBundlesCMS, bundles‑cms, and media‑bundle components. Any installation of version 7.3.1 or earlier is vulnerable. The issue is resolved in version 7.3.2 and later releases.

Risk and Exploitability

The CVSS base score of 7.2 highlights a high‑severity risk. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must first authenticate as a backend user with media upload privileges, which is typically granted to site administrators. Once authenticated, the attacker can upload malicious code and execute it via the web server, resulting in complete compromise of the affected system. The lack of publicly available exploit code does not reduce the risk, as the flaw is straightforward to script and deploy under the required authentication context.

Generated by OpenCVE AI on October 5, 2026 at 17:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Kunstmaan CMS installation to version 7.3.2 or a later release that removes the blacklist bypass.
  • If an upgrade is not feasible immediately, reconfigure the media upload functionality to enforce a strict whitelist of allowed extensions, ensuring that executable types such as .php, .exe, .html, and others are prohibited.
  • Move the media upload directory outside the web‑accessible root or configure the web server to serve uploaded files with a non‑executable MIME type, preventing possible execution of malicious uploads.

Generated by OpenCVE AI on October 5, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklisted_extensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An authenticated backend user with media access can upload a mixed-case executable extension such as PHP that bypasses the check and is stored in the web-accessible media directory with an executable lowercase extension. The default blacklist also omits several server-executable extension types, allowing the same code-execution impact where the web server executes uploaded files. This issue is fixed in version 7.3.2.
Title Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T15:46:21.959Z

Reserved: 2026-10-02T14:59:11.775Z

Link: CVE-2026-104890

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T16:17:06.270

Modified: 2026-10-05T16:17:06.270

Link: CVE-2026-104890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T17:30:11Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type