CVE-2026-5704
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injectio
CVSS
5.0
Medium
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Apr 6, 2026 · Last modified: Sep 22, 2026 · CWE-434
0.4%EPSS · 30 days0.4%
2026-08-252026-09-22
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:61581
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:61586
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:61783
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:66018
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:66514
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:70390
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-5704
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2455360
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2026/04/11/10
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2026/04/11/11
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2026/04/12/2
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-958306.3 MED—
———A security flaw has been discovered in theRealSain Pixtream up to 866afd4f0cea812b918780fb74b67dccf8c4d6a0. This issue affects some unknown processing of the file /post_upload.php. The manipulation of the argument media results in unrestricted upload. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.12hCVE-2026-958206.3 MED—
———A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php?section=admin1. Performing a manipulation of the argument image results in unrestricted upload. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.13hCVE-2026-884198.8 HIG—
———An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrary PHP code on the server, because the stored file extension is taken verbatim from the client-supplied filename with no extension allowlist or content validation and the file is written to the web-accessible uploadfile/ directory, from which the web server executes PHP.16hCVE-2026-955007.3 HIG—
——0A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The manipulation of the argument filename/content leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.17hCVE-2026-954997.3 HIG—
——0A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.17hCVE-2026-887388.8 HIG15.6%
——5Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.17h