CVE-2026-3748

A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-code/src/main/java/com/bytedesk/core/upload/UploadRestController.java of the component SVG File Handler. Performing a manipulation results in unrestricted upload. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.4.5.1 is able to mitigate this issue. The patch is named 975e39e4dd527596987559f56c5f9f973f64eff7. Upgrading the affected component is recommended.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bytedesk:bytedesk:*:*:*:*:*:*:*:*

History

10 Mar 2026, 18:52

Type Values Removed Values Added
CPE cpe:2.3:a:bytedesk:bytedesk:*:*:*:*:*:*:*:*
First Time Bytedesk
Bytedesk bytedesk
Summary
  • (es) Una falla de seguridad ha sido descubierta en Bytedesk hasta 1.3.9. Esto afecta la función uploadFile del archivo source-code/src/main/java/com/bytedesk/core/upload/UploadRestController.java del componente SVG File Gestor. Realizar una manipulación resulta en una carga irrestricta. La explotación remota del ataque es posible. El exploit ha sido publicado y puede ser usado para ataques. Actualizar a la versión 1.4.5.1 puede mitigar este problema. El parche se llama 975e39e4dd527596987559f56c5f9f973f64eff7. Se recomienda actualizar el componente afectado.
References () https://github.com/Bytedesk/bytedesk/ - () https://github.com/Bytedesk/bytedesk/ - Product
References () https://github.com/Bytedesk/bytedesk/commit/975e39e4dd527596987559f56c5f9f973f64eff7 - () https://github.com/Bytedesk/bytedesk/commit/975e39e4dd527596987559f56c5f9f973f64eff7 - Patch
References () https://github.com/Bytedesk/bytedesk/issues/18 - () https://github.com/Bytedesk/bytedesk/issues/18 - Exploit, Vendor Advisory, Issue Tracking
References () https://github.com/Bytedesk/bytedesk/issues/18#issue-3993448721 - () https://github.com/Bytedesk/bytedesk/issues/18#issue-3993448721 - Exploit, Vendor Advisory, Issue Tracking
References () https://github.com/Bytedesk/bytedesk/issues/18#issuecomment-3976672973 - () https://github.com/Bytedesk/bytedesk/issues/18#issuecomment-3976672973 - Exploit, Vendor Advisory, Issue Tracking
References () https://github.com/Bytedesk/bytedesk/releases/tag/v1.4.5.1 - () https://github.com/Bytedesk/bytedesk/releases/tag/v1.4.5.1 - Release Notes
References () https://vuldb.com/?ctiid.349726 - () https://vuldb.com/?ctiid.349726 - Permissions Required
References () https://vuldb.com/?id.349726 - () https://vuldb.com/?id.349726 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.768028 - () https://vuldb.com/?submit.768028 - Third Party Advisory, VDB Entry

08 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-08 16:16

Updated : 2026-03-10 18:52


NVD link : CVE-2026-3748

Mitre link : CVE-2026-3748

CVE.ORG link : CVE-2026-3748


JSON object : View

Products Affected

bytedesk

  • bytedesk
CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type