Beveiligingsadvies

CVE-2026-40040

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-04-13 18:10:56
Laatst bijgewerkt 2026-05-12 01:46:28
Toegewezen door VulnCheck
CVSS-score 8.8
Status PUBLISHED

Beschrijving

Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint. Attackers can upload executable files .php5 scripts to web-accessible directories and execute them to achieve remote code execution on the server.