Junglewise Threat Intelligence

CVE-2026-53691: Redeight CMS unrestricted file upload in FileAdd endpoint

CVE-2026-53691 · Severity: info · CVSS 8.6 · Published 2026-06-30

Technologies: Redeight CMS. Vendors: Redeight.

Executive brief

Redeight CMS, a content management system, contains a security flaw that allows users with login access to upload malicious files. By uploading a specially crafted script, an attacker can take full control of the web server. This could lead to the theft of sensitive data, website defacement, or a total service outage.

Technical details

An unrestricted file upload vulnerability exists in Redeight CMS 1.0 within the '/admin/index.php?module=pages&mode=FileAdd' endpoint. The application fails to validate file extensions or MIME types for uploaded files. An authenticated attacker can exploit this by uploading a malicious PHP script to the '/uploads/files/' directory, which is publicly accessible. Because the web server executes scripts in this directory, the attacker can achieve Remote Code Execution (RCE) on the underlying host.

Affected products

  • Redeight Redeight CMS 1.0

Timeline

  • 2026-06-30: disclosed: Vulnerability disclosed by CERT.PL
  • 2026-06-30: advisory

References

Related threats