CVE-2026-80050
ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authen
CVSS
6.5
Medium
EPSS
0.4%
p35
KEV
—
Exploit Today
11
0-100
Published: Aug 25, 2026 · Last modified: Sep 24, 2026 · CWE-434
0.2%EPSS · 30 days0.4%
2026-08-272026-09-24
ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. Attackers can initialize chunked uploads, send file parts, and complete uploads to leave arbitrary files in the storage backend accessible via web server URLs.
- github.comhttps://github.com/continew-org/continew-admin
- github.comhttps://github.com/continew-org/continew-admin/blob/v4.1.0/continew-system/src/main/java/top/continew/admin/system/controller/MultipartUploadController.java
- github.comhttps://github.com/continew-org/continew-admin/issues/221
- www.vulncheck.comhttps://www.vulncheck.com/advisories/continew-admin-through-4.1.0-missing-authorization-and-file-type-allowlist-on-multipart-upload-endpoints
- github.comhttps://github.com/continew-org/continew-admin/issues/221
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-132499.8 CRI—
———An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication.
An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability.21hCVE-2026-132488.8 HIG—
———An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticated user with access to the admin or itadmin account to submit commands written in the Intermec Fingerprint programming language directly to the printer ’s internal command interpreter.
An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industrial Printer firmware F10.22.030745, which includes a fix for this vulnerability.21hCVE-2026-96515——
——0This
vulnerability exists in the Netlink ICT HG323RW router due to insufficient
authorization and input validation controls in the diagnostic script import
functionality. An authenticated attacker could exploit this vulnerability by
uploading and executing a specially crafted script through the web management
interface.
Successful exploitation of this vulnerability
could allow the attacker to execute arbitrary operating system commands with
root privileges resulting in complete compromise of the affected device.1dCVE-2026-933529.8 CRI47.5%
——14Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .pht file that passes all validation in MediaUploader::verifyExtension() and File::sanitizeFileName() because pht is not present in the blocklist, causing the file to be written to disk and executed as PHP when requested, enabling remote code execution with the privileges of the web server process.20hCVE-2026-965137.3 HIG18.0%
——5A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the file AddProductCode.php. The manipulation of the argument image results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure but did not respond in any way.2dCVE-2026-5695—20.0%
——6Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code remotely (demonstrated by uploading the EICAR test file), which could result in the system being completely compromised.1d