
CVE-2026-25099 Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed,… https://www.cve.org/CVERecord?id=CVE-2026-25099
Post summary
The CVE discloses an authenticated API‑plugin flaw in Bludit that allows unrestricted file uploads, potentially leading to code execution; no PoC, exploitation, or patch details are provided.
