Junglewise Threat Intelligence

CVE-2026-5695: Microweber administration panel arbitrary file upload

CVE-2026-5695 · Severity: info · Published 2026-09-23

Technologies: Microweber. Vendors: Microweber.

Executive brief

Microweber is a website builder and online shop platform. An authenticated administrator can upload arbitrary files to the server without restrictions, allowing them to execute malicious code and fully compromise the system. No patch is currently available.

Technical details

CWE-434 arbitrary file upload vulnerability in the Microweber administration panel's upload forms lacks proper file validation. Authenticated users with high privileges can upload executable files directly to the server. Remote code execution is achievable through file upload, demonstrating complete system compromise.

Affected products

  • Microweber Microweber v2.0.19

Timeline

  • 2026-06-01: disclosed: INCIBE-CERT published coordinated advisory
  • 2026-09-23: advisory: CVE-2026-5695 published

References

Related threats