CVE-2026-48946

The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2 Author can upload a `shell.php`, then fetch `/media/k2/attachments/shell.php` and execute arbitrary PHP code in the web server's context.
References
Link Resource
https://www.getk2.org/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:joomlaworks:k2:*:*:*:*:*:joomla\!:*:*

History

26 Jun 2026, 17:43

Type Values Removed Values Added
References () https://www.getk2.org/ - () https://www.getk2.org/ - Product
First Time Joomlaworks
Joomlaworks k2
CPE cpe:2.3:a:joomlaworks:k2:*:*:*:*:*:joomla\!:*:*

25 Jun 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3

25 Jun 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-25 16:16

Updated : 2026-06-28 19:16


NVD link : CVE-2026-48946

Mitre link : CVE-2026-48946

CVE.ORG link : CVE-2026-48946


JSON object : View

Products Affected

joomlaworks

  • k2
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type