Junglewise Threat Intelligence

CVE-2026-36467: CuteNews unrestricted file upload in media manager

CVE-2026-36467 · Severity: high · CVSS 7.2 · Published 2026-09-21

Technologies: CuteNews. Vendors: CuteNews.

Executive brief

CuteNews is a content management system that allows site administrators to publish news and manage media files. An authenticated administrator with access to the Media Manager can upload executable files that bypass file type restrictions, allowing the attacker to execute arbitrary code on the web server and gain full control of the underlying system through a reverse shell.

Technical details

The media.php module in CuteNews 2.1.2 fails to properly validate uploaded file types, allowing an authenticated user with Media Manager access to upload dangerous file types such as PHP scripts. An attacker with valid credentials can exploit this to achieve remote code execution in the context of the web application, establishing a reverse shell for complete server compromise.

Affected products

  • CuteNews CuteNews 2.1.2

Timeline

  • 2026-09-21: disclosed

References

Related threats