CVE-2021-23394Active Exploitation(std42 / elfinder)

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch std42 elfinder systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • elfinder

Threat summary

  • Active exploitation appears in 1 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
elfinder

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-06: 1Exploit Tool / Code · 2026-02-06: 1Active Exploitation · 2026-02-06: 1Patch / Workaround · 2026-02-06: 1Technical Details · 2026-02-06: 102-06
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Ostorlab@OstorlabSec
    Active Exploitation

    🚨 CVE-2021-23394 : CRITICAL REMOTE CODE EXECUTION ALERT 🚨 An unauthenticated remote code execution vulnerability has been disclosed in elFinder, a widely deployed web-based file manager, exploitable via malicious `.phar` file uploads and requiring no authentication or user interaction. Risk Severity: - High (CVSS 8.1, active exploitation, public exploits available, CISA KEV listed) Impact: - Unauthenticated remote code execution - Full web server compromise - Persistent webshell deployment - Sensitive data exfiltration - Ransomware and cryptominer installation Root Cause: - CWE-434 (Unrestricted File Upload) combined with CWE-502 (Deserialization of Untrusted Data). elFinder fails to block `.phar` file uploads. When accessed, PHP automatically deserializes malicious metadata embedded in the archive, triggering arbitrary code execution. Attackers can: - Upload a crafted `.phar` file via exposed elFinder upload endpoints - Trigger PHP deserialization by directly requesting the uploaded file - Execute arbitrary PHP code with web server privileges - Deploy persistent backdoors, mine cryptocurrency, or launch ransomware Are You Affected? - Vulnerable: All elFinder versions prior to 2.1.58 - Exposure: Internet-facing elFinder instances with upload functionality enabled Immediate Action Required: - Update: Upgrade to elFinder 2.1.58 or later immediately - Mitigation: Disable file uploads or block `.phar` extensions at the WAF/web server level if patching is delayed - Audit: Hunt for `.phar` files in upload directories and review logs for connector abuse This vulnerability is actively exploited and listed in CISA KEV. Unpatched systems should be considered compromised. 🛡️ #ostorlabCVE

    Post summary

    The alert highlights CVE‑2021‑23394 as a critical remote code execution flaw in elFinder that is actively exploited, with public exploits and a CISA KEV listing, and urges immediate patching or mitigation.

    00000102
    581 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstd42elfinder---

Explore more