Description
A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function Upload::upload of the file ThinkPHP/Library/Think/Upload.class.php. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-07
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted Remote File Upload
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in Light0011 CMS’s ThinkPHP Upload class, allowing an attacker to upload arbitrary files under the control of a remote user. Because no validation or restriction is imposed on accepted file types or locations, a malicious actor can place executable code or web shells on the server, potentially leading to full server compromise. The weakness is specified as CWE-284 (Improper Access Control) and CWE-434 (Unrestricted Upload of File with Dangerous Type).

Affected Systems

Light0011 CMS, a rolling‑release project with an unmaintained issue tracker, has no pinned version numbers. The flaw affects every release of the CMS that includes the vulnerable Upload class until a patch is applied or the upload functionality is removed. The vendor has not yet responded to the reported issue and has not released a fix.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity vulnerability. EPSS is currently unavailable, so the probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Though the exploit has been released publicly, no confirmed exploitation has been reported. The attack can be carried out remotely by simply sending a crafted request to the upload endpoint, and the lack of payload restrictions makes exploitation straightforward for an attacker with network access to the CMS.

Generated by OpenCVE AI on September 7, 2026 at 15:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor release or patch once available; update the CMS to the newest commit that fixes the upload logic.
  • If an immediate patch is not available, disable the upload feature entirely or implement a strict file‑type whitelist and size limits to prevent arbitrary code from being stored on the server.
  • Deploy a web application firewall or file‑content scanner to block suspicious uploads and detect potential web shells before they become active.

Generated by OpenCVE AI on September 7, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function Upload::upload of the file ThinkPHP/Library/Think/Upload.class.php. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
Title light0011 cms Upload.class.php upload unrestricted upload
First Time appeared Light0011
Light0011 cms
Weaknesses CWE-284
CWE-434
CPEs cpe:2.3:a:light0011:cms:*:*:*:*:*:*:*:*
Vendors & Products Light0011
Light0011 cms
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-11T20:35:00.640Z

Reserved: 2026-09-06T18:11:05.216Z

Link: CVE-2026-86305

cve-icon Vulnrichment

Updated: 2026-09-11T20:02:54.543Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T13:20:39.753

Modified: 2026-09-11T21:17:44.957

Link: CVE-2026-86305

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T16:00:13Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-434

    Unrestricted Upload of File with Dangerous Type