Junglewise Threat Intelligence

CVE-2026-2334: vsDesk missing server-side file validation in CSV import

CVE-2026-2334 · Severity: info · CVSS 9.4 · Published 2026-08-20

Technologies: vsDesk. Vendors: vsDesk.

Executive brief

vsDesk is a web-based help desk and ticket management platform used by organizations to track customer requests and internal issues. Administrators with valid credentials can upload malicious files by bypassing client-side validation checks in the CSV import feature, leading to arbitrary code execution on the web server and potential compromise of customer data and system availability.

Technical details

The vulnerability is a missing server-side file extension validation flaw in vsDesk v14.0101's "Import via CSV" feature. The application relies solely on client-side validation to restrict file types; an authenticated attacker with administrative privileges can craft a direct HTTP request or disable client-side checks to upload arbitrary file types (e.g., PHP shells) to the web server. No server-side verification of file extensions or content-type occurs before processing. Successful exploitation leads to remote code execution in the context of the web application helper process. The issue was fixed in version 14.0402 and later, with enhanced server-side validation and relocation of temporary CSV files to a protected directory.

Affected products

  • vsDesk vsDesk 14.0101, and possibly others before 14.0402

Timeline

  • 2026-08-20: disclosed
  • 2026-04-21: patched: Version 14.0402 and later contain the fix

References

Related threats