Junglewise Threat Intelligence

CVE-2026-86305: light0011 cms unrestricted file upload in Upload::upload

CVE-2026-86305 · Severity: high · CVSS 7.3 · Published 2026-09-07

Technologies: Light0011 CMS.

Executive brief

light0011 is a news and content management system built on Bootstrap and ThinkPHP. The application contains an unrestricted file upload vulnerability in its upload handler that accepts arbitrary file types, MIME types, and sizes without validation. On servers with executable upload directories, this flaw allows unauthenticated attackers to upload and execute malicious code, leading to complete server compromise.

Technical details

The vulnerability is an unrestricted file upload in the Upload::upload() function (ThinkPHP/Library/Think/Upload.class.php lines 17-31) used by multiple controllers including the unauthenticated Home/User upload action (App/Home/Controller/UserController.class.php:60-74). The root cause is that the application sets only the rootPath parameter while relying on ThinkPHP's permissive defaults for mimes=[], exts=[], and maxSize=0; validation checks at lines 285-305 and 342-360 allow all file types when these restrictions are empty. The attack is remotely exploitable without authentication; an attacker can upload arbitrary files via POST multipart requests. On deployments where the upload directory is web-accessible and PHP execution is enabled, this results in unauthenticated remote code execution. No patch has been released; the project uses a rolling release model and has not responded to the early security report.

Affected products

  • light0011 cms commit f72cf46f601efb2a0618c3814cc2f61380b38930 and earlier

Timeline

  • 2026-07-18: disclosed: Issue reported on GitHub
  • 2026-09-07: advisory: CVE-2026-86305 published

References