CVE-2026-25099

Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bludit:bludit:*:*:*:*:*:*:*:*

History

01 Apr 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:a:bludit:bludit:*:*:*:*:*:*:*:*
First Time Bludit
Bludit bludit
References () https://cert.pl/posts/2026/03/CVE-2026-25099 - () https://cert.pl/posts/2026/03/CVE-2026-25099 - Third Party Advisory
References () https://github.com/bludit/bludit/releases/tag/3.18.4 - () https://github.com/bludit/bludit/releases/tag/3.18.4 - Release Notes

27 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-27 12:16

Updated : 2026-04-01 14:16


NVD link : CVE-2026-25099

Mitre link : CVE-2026-25099

CVE.ORG link : CVE-2026-25099


JSON object : View

Products Affected

bludit

  • bludit
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type