peter bassill · operator
$ cve CVE-2026-25099 JSON

CVE-2026-25099 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 1.9% (pctl 79)

Patch early

A public exploit exists.

Description

Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS1.92% — more likely to be exploited than 79% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2026-03-27
Last modified2026-06-17

Affected (1)

VendorProduct
bluditbludit

Public exploits

SourceTitleDate
exploit-dbBludit CMS 3.18.4 - RCE2026-05-07

References

→ the Explorer  ·  watch your stack  ·  NVD