Description
An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution (RCE) within the context of the web application. 
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.
Published: 2026-08-20
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated attacker with administrative privileges can bypass client‑side file validation in the Import via CSV component of vsDesk v14.0101 because the application performs no server‑side file extension check. This flaw allows uploading an arbitrary file that is then executed as code in the web application context, giving the attacker full remote code execution capabilities and compromising confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects the vsDesk application, specifically version 14.0101. The vendor has released a patch in versions 14.0402 and later that implements proper server‑side validation of uploaded file extensions.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity. While the EPSS score is unavailable, the absence of a known exploitation status in CISA's KEV catalog does not reduce the importance of applying the patch. The attack requires administrative access, meaning the threat surface is limited to compromised or poorly protected admin credentials, but once active the attacker can run arbitrary code on the affected system.

Generated by OpenCVE AI on August 21, 2026 at 02:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading to vsDesk version 14.0402 or newer, which adds server‑side file type validation.
  • Restrict the Import via CSV feature to the minimum set of verified administrative accounts and enforce multi‑factor authentication for those accounts to reduce the risk of credential compromise.
  • Implement log monitoring for the file upload endpoint to detect and alert on attempts to upload disallowed file types.

Generated by OpenCVE AI on August 21, 2026 at 02:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Vsdesk
Vsdesk vsdesk
Vendors & Products Vsdesk
Vsdesk vsdesk

Thu, 20 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution (RCE) within the context of the web application.  Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.
Title ) Missing Server-Side File Extension Validation in vsDesk
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Kaspersky

Published:

Updated: 2026-08-21T20:08:38.818Z

Reserved: 2026-02-11T10:03:03.753Z

Link: CVE-2026-2334

cve-icon Vulnrichment

Updated: 2026-08-21T20:06:35.262Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T18:16:26.047

Modified: 2026-08-31T19:33:11.197

Link: CVE-2026-2334

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T02:45:04Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type